← All posts
Cloud Security14 Apr 2026·1 min read·By

Cloud access keys that outlive the people who created them

Share

A short note on long-lived keys and forgotten service accounts, plus a half-hour review you can do this week.

Short one this time.

A pattern we keep running into on cloud reviews: an access key created years ago by a developer who has since left, still active, with far more permission than whatever it's used for. Sometimes nobody knows what it's used for at all. Sometimes it's sitting in a CI pipeline, or in a Git repo that turned out to be public.

A review you can do in about half an hour, whichever cloud you're on:

  • List every access key and service account with its last-used date.
  • Anything unused for 90 days, disable it (don't delete yet). If nothing breaks in two weeks, delete it.
  • Anything with admin or owner rights, ask who needs that and write down the answer.
  • Check the break-glass admin account has MFA, and that its password isn't saved in someone's browser.

Where the platform supports it, move CI jobs and workloads to short-lived credentials (IAM roles on AWS, workload identity federation on GCP, managed identities on Azure) so there's no long-lived key to leak in the first place.

Then set a calendar reminder to do it again in three months. That part matters more than it sounds.

Share

Comments (0)

No public comments yet.

Leave a comment

Comments are checked by hand before they go live.

Most read on the blog

  1. 1Zero trust when you have one IT person and three branches
  2. 2What we'd put on a one-page security update for the board
  3. 3Logging for companies that can't justify a SIEM yet
  4. 4Ransomware prep for mid-sized companies: start with the restore
  5. 5Is your guest Wi-Fi on the same network as the accounts PC?

Related posts