Stepwork logoStepwork logo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
  1. Home
  2. Marketplace
  3. Deactivate access keys for user in AWS

Deactivate access keys for user in AWS

Automatically deactivate a user’s IAM access keys in AWS from a Slack request with Stepwork. Find every active key and deactivate it, ending programmatic access.

Shaun MacLellanFounder

Book a DemoSee the process
Use case
Access managementIT
Best for
Cloud Administrator, IT Administrator
Applications used
  • AWS
  • Slack
Business outcome
Risk reduction

On this page

  1. The problem
  2. The outcome
  3. The process
  4. Why Stepwork
  5. Similar use cases
  6. FAQ
IT
  • AWS

Deactivate access keys

One Slack request. Every active key turned off.

Book a Demo

The problem

Old keys outlive the people who made them.

Access keys sit in scripts, laptops, and config files long after anyone remembers them. They keep working until someone deactivates them in IAM.

Most keys are only looked at during a security review, and by then a leaked or forgotten key has had months to be used. Turning one off by hand means finding the user, opening their credentials, and checking each key.

The outcome

Programmatic access ends, and the keys are kept

Stepwork deactivates every active access key on the user. Anything signing requests with those keys stops working. The keys are deactivated, not deleted, so one can be turned back on if a service turns out to need it.

  • Every active key on the user is deactivated.
  • Keys are kept, so they can be reactivated.
  • The Slack reply lists each key that was turned off.

The process

From Slack request to deactivated keys

A teammate posts the request in Slack. Stepwork deactivates the keys on the user’s security credentials in the IAM console.

  1. Step 1

    Request it in Slack

    A teammate posts the IAM user name in the security channel. That message starts the flow, and Stepwork records who asked and when.

    Slack message in #it-security asking to deactivate access keys for IAM user sam.patel, with Stepwork confirming the flow started
  2. Step 2

    Find the user

    Stepwork signs in to the AWS console, opens IAM, and finds the user with that exact name. If there is no match, the run stops instead of guessing.

    AWS IAM user sam.patel with both access keys still Active
  3. Step 3

    Deactivate each active key

    On the user’s security credentials, Stepwork deactivates every key marked Active. An IAM user can have up to two.

    AWS confirmation to deactivate both access keys for sam.patel
  4. Step 4

    Confirm and reply in Slack

    Stepwork checks that no key on the user still reads Active, then posts the IDs of the keys it turned off in Slack.

    AWS IAM security credentials for sam.patel with both access keys Inactive
Slack message in #it-security asking to deactivate access keys for IAM user sam.patel, with Stepwork confirming the flow started
AWS IAM user sam.patel with both access keys still Active
AWS confirmation to deactivate both access keys for sam.patel
AWS IAM security credentials for sam.patel with both access keys Inactive

Why Stepwork

Only the status changes

Credentials stay in 1Password. Stepwork signs in to the AWS console with a vault reference and changes only the status of keys that read Active. It never creates, deletes, or reads a secret key.

Credentials
Book a Demo

Similar use cases

Similar use cases

  • Deactivate IAM user in AWSDisables console access and deactivates credentials for an IAM user in the AWS console.Learn more
  • Remove user from Identity Center in AWSRemoves a user's IAM Identity Center assignments and disables their access across AWS accounts.Learn more
  • Remove outside collaborator from GitHub reposFinds every repository where a given outside collaborator has access and removes them from each.Learn more

FAQ

Common questions

  • Post the IAM user name in Slack. Stepwork opens the user’s security credentials in IAM and deactivates every active key.
  • Yes. Deactivating keeps the key. An admin can make it active again in IAM, or delete it later.
  • No. Only the access keys change. To end both, deactivate the IAM user.
    Deactivate IAM user in AWS

See it run on a process you already repeat

Bring one. We will show you what it looks like as a flow and what each run records.

Book a Demo
Stepwork

Deterministic agents for work that must run the same way every time.

ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work AlternativeFAQ
Terms and ConditionsPrivacy PolicyData Processing AgreementSubprocessors

2261 Market Street #4481, San Francisco, CA 94114, USA

Loot Discount inc dba Stepwork

© 2026 Stepwork. All rights reserved.