Disabling Amazon S3 access control lists with S3 Inventory
Blog
This article explains how to use Amazon S3 Inventory reports to audit and disable Access Control Lists (ACLs) by migrating to IAM policies and bucket policies.
- S3 Inventory reports now include object ACL metadata in JSON format
- ACLs displayed with owner, grantee, and permission information
- Use Athena to query inventory and identify objects with specific ACL permissions
- Migrate cross-account ACL access using IAM roles and S3 bucket policies
- Disable ACLs after validating all permissions work via policies
- Cost-effective alternative to API calls for auditing ACL usage at scale
This enables customers to audit existing ACLs, migrate permissions to policies, and disable ACLs safely without disrupting applications.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.