Updated on 2024-05-22 GMT+08:00

Key Rotation Check

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

access-keys-rotated

Identifier

access-keys-rotated

Description

If there is an access key that has not been rotated for longer than the specified time, the result is noncompliant.

Tag

iam

Trigger Type

Periodic

Filter Type

iam.users

Configure Rule Parameters

maxAccessKeyAge: indicates the maximum number of days that the AK/SK is allowed to remain unchanged. The default value is 90 days.