Deactivate access keys for user in AWS
Automatically deactivate a user’s IAM access keys in AWS from a Slack request with Stepwork. Find every active key and deactivate it, ending programmatic access.
- Use case
- Access managementIT
- Best for
- Cloud Administrator, IT Administrator
- Applications used
AWS
Slack
- Business outcome
- Risk reduction
The problem
Old keys outlive the people who made them.
Access keys sit in scripts, laptops, and config files long after anyone remembers them. They keep working until someone deactivates them in IAM.
Most keys are only looked at during a security review, and by then a leaked or forgotten key has had months to be used. Turning one off by hand means finding the user, opening their credentials, and checking each key.
The outcome
Programmatic access ends, and the keys are kept
Stepwork deactivates every active access key on the user. Anything signing requests with those keys stops working. The keys are deactivated, not deleted, so one can be turned back on if a service turns out to need it.
- Every active key on the user is deactivated.
- Keys are kept, so they can be reactivated.
- The Slack reply lists each key that was turned off.
The process
From Slack request to deactivated keys
A teammate posts the request in Slack. Stepwork deactivates the keys on the user’s security credentials in the IAM console.
- Step 1
Request it in Slack
A teammate posts the IAM user name in the security channel. That message starts the flow, and Stepwork records who asked and when.

- Step 2
Find the user
Stepwork signs in to the AWS console, opens IAM, and finds the user with that exact name. If there is no match, the run stops instead of guessing.

- Step 3
Deactivate each active key
On the user’s security credentials, Stepwork deactivates every key marked Active. An IAM user can have up to two.

- Step 4
Confirm and reply in Slack
Stepwork checks that no key on the user still reads Active, then posts the IDs of the keys it turned off in Slack.

Why Stepwork
Only the status changes
Credentials stay in 1Password. Stepwork signs in to the AWS console with a vault reference and changes only the status of keys that read Active. It never creates, deletes, or reads a secret key.
Similar use cases
Similar use cases
Deactivate IAM user in AWSDisables console access and deactivates credentials for an IAM user in the AWS console.
Remove user from Identity Center in AWSRemoves a user's IAM Identity Center assignments and disables their access across AWS accounts.
Remove outside collaborator from GitHub reposFinds every repository where a given outside collaborator has access and removes them from each.
FAQ





