IAM user should not have more than one active access key
Medium
AWS
General
aws-iam-user-iam-user-more-than
Applies to
AWS::IAM::User
What CGPulse checks
A resource passes this rule when accessKeyCount must be less than 2. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Remove extra access keys (keep at most one) and prefer IAM roles with temporary credentials. In AWS Console: IAM > Users > Security credentials > delete extra keys. See: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html
Terraform
# Remove extra access keys and prefer IAM roles with temporary credentials
# Use aws_iam_access_key resource — limit to one per user
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related AWS rules
- ACM certificate must be eligible for renewal
- ACM certificate must be in issued status
- Amplify app should have basic auth disabled for production
- API Gateway REST API must have an endpoint configuration
- API Gateway V2 API must be properly configured
- App Runner service must have encryption enabled
- AppSync API must have logging configured
- AppSync API must have X-Ray tracing enabled