(I am not fond on vendor’s blogs as the signal to noise ratio is very low, since they are written to please search engines more than engineers… but Scott Piper gets a pass.)
I found this insightful, access keys are such a liability that is better to tame as early as possible. Fixing the problem a scale is a lot more challenging.
Getting rid of long living access keys is such a win.
Adding an SCP to block creation is mentioned last in the blog post, but I’d sat that’s the first thing one should do. That way the problem won’t grow as you remove the existing ones (which might take a lot of time).
Good blog post indeed! Not exactly ground breaking but considering how common the problem is I don’t blame them for writing it.