Amazon S3 Inventory’s capability to include access control lists (ACLs) as object metadata in inventory reports is now available in AWS GovCloud (US) Regions. This allows you to easily review ACLs on all of your objects to simplify review of access permissions. ACLs were the original way to manage object access when S3 launched in 2006. Now, when migrating to IAM-based bucket policies for access control, you can easily review all of the object ACLs in your buckets before enabling S3 Object Ownership.
S3 Inventory provides a complete list of objects in a bucket and their corresponding metadata. The Object ACLs fields include details about the object owner and the grantee along with their permission granted. You can now activate reporting on object ACLs by editing existing S3 Inventory configurations in the AWS Management Console or API.
By enabling S3 Object Ownership, you can change how S3 performs access control for a bucket so that only IAM policies are used. S3 Object Ownership’s ‘Bucket owner enforced’ setting disables ACLs for your bucket and the objects in it, and updates every object so that each object is owned by the bucket owner. We recommend that you carefully review your use of ACLs with inventory reports, migrate to IAM-based bucket policies, and then disable ACLs with S3 Object Ownership. For more information, see Controlling ownership of objects and disabling ACLs for your bucket.
Amazon S3 Inventory support for Object ACL is generally available at no additional charge in all AWS Commercial and AWS GovCloud (US) Regions, where Amazon S3 Inventory is available. To learn more, please visit Amazon S3 Inventory and Amazon S3 pricing.
Categories:
Source: Amazon Web Services
Latest Posts
- Dynamics 365 Customer Service – Protect sensitive information in emails with data sensitivity labels [MC1276446]
![Dynamics 365 Customer Service - Protect sensitive information in emails with data sensitivity labels [MC1276446] 2 pexels pixabay 144234](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Chat visibility in the Microsoft 365 Copilot App [MC1197289]
![(Updated) Chat visibility in the Microsoft 365 Copilot App [MC1197289] 3 pexels thepaintedsquare 820904](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- AWS Private CA now supports customer managed permissions for cross-account sharing

- AWS Billing and Cost Management Dashboards Now Supports Scheduled Email Delivery


![Dynamics 365 Customer Service - Protect sensitive information in emails with data sensitivity labels [MC1276446] 2 pexels pixabay 144234](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-pixabay-144234-150x150.webp)
![(Updated) Chat visibility in the Microsoft 365 Copilot App [MC1197289] 3 pexels thepaintedsquare 820904](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-thepaintedsquare-820904-150x150.webp)


