GUIDE

Stale IAM access keys.

August 27, 2026

Age vs last used

Long-lived IAM user access keys are still how a lot of CI jobs, old laptops, and “temporary” scripts talk to AWS. CIS and most scanners flag keys older than 90 days from create date, even if they were used this morning. Last-used is a different question: a key that has not been used in 90 days is often safe to deactivate; a 200-day-old key that deploys production every hour needs rotation, not a surprise delete.

Root access keys are worse. If the root user has any access key, delete it. Console password + MFA for break-glass; never CI as root.

Find it yourself

aws iam generate-credential-report
aws iam get-credential-report --query Content --output text | base64 --decode > iam-report.csv

The CSV has access_key_1_active, access_key_1_last_rotated, and access_key_1_last_used_date (same for key 2). Sort on rotation date and last used. Per user:

aws iam list-access-keys --user-name <user>
aws iam get-access-key-last-used --access-key-id <key-id>

Deactivate first, wait, then delete:

aws iam update-access-key --user-name <user> \
  --access-key-id <key-id> --status Inactive

Console: IAM → Users → the user → Security credentials → Deactivate, then Delete once nothing pages. Create a new key, put it in Secrets Manager / the CI secret store, then retire the old one. Two active keys per user is the rotation window AWS gives you; do not leave both forever.

Stop making more of them

  • Prefer an IAM role for EC2, Lambda, ECS, and GitHub Actions (OIDC). No long-lived key on disk.
  • If a human needs CLI access, Identity Center (SSO) short-lived creds beat an IAM user key.
  • Turn on a budget or CloudTrail metric for CreateAccessKey if you want to notice the next intern key.

Users with only programmatic keys (no console password) are a different MFA story — there is nothing to MFA. Rotate those keys; do not confuse them with console users missing MFA.

Where PostureRadar fits

PostureRadar lists IAM users’ active keys and flags anything older than 90 days (medium) or 180 days (high), plus root keys on the root-account check. It uses create date, not last-used — so a still-working CI key will show up until you rotate it. It's $39 per account per month, weekly; the remediation guidance is deactivate, then delete.

Related: Public S3 buckets · Why AWS Config gets expensive · Scheduling Prowler email reports