How to Configure Amazon S3 Block Public Access for a Bucket
CS Browser
Free Windows client for Amazon S3 and Amazon S3 compatible storage services
 
Follow

Amazon S3 Block Public Access Configuration

Amazon S3 Block Public Access Overview

Amazon S3 Block Public Access helps protect buckets and files from unintended public access granted through access control lists (ACLs) or bucket policies. The four available settings can be enabled independently, depending on how the bucket is intended to be used.

Since April 2023, Amazon S3 enables all four Block Public Access settings and disables ACLs by default for every new bucket in every AWS Region. AWS recommends keeping these protections enabled unless public access is specifically required.

CS Browser manages the bucket-level Block Public Access configuration. Amazon S3 evaluates these settings together with any account- and organization-level settings and applies the most restrictive combination. Disabling a setting for an individual bucket cannot override a stricter setting configured for its account or AWS organization.

Block Public Access does not delete existing ACLs or bucket policies. If a protection is later disabled, permissions stored in an existing ACL or policy may become effective again.

If you need to use the Make Public command for a bucket created with the new Amazon S3 defaults, follow the instructions for restoring public access. Change only the settings required for your use case.

How to Manage Amazon S3 Block Public Access

  1. Select the bucket, open the Buckets menu, and choose Public Access Block Configuration.. (Ctrl+B).

    Buckets menu with Public Access Block Configuration selected
    Buckets > Public Access Block Configuration.. (Ctrl+B)

    The Public Access Block Configuration dialog will open:

    Public Access Block Configuration dialog with all four protection settings enabled
    Amazon S3 Block Public Access settings for the selected bucket

    Enable public access block configuration for [bucket] - Stores a bucket-level Block Public Access configuration. Clearing this check box removes the bucket-level configuration; account- or organization-level settings can still block public access.

    Block public ACL - Rejects requests that would add a public access control list (ACL) to the bucket or a file. Turning this option on causes the following behavior:

    • PUT Bucket ACL and PUT Object ACL calls fail if the specified ACL is public.
    • PUT Object calls fail if the request includes a public ACL.
    • PUT Bucket calls fail if the request includes a public ACL.
    • Existing policies and ACLs are not changed.

    Block public policy - Rejects a new or updated bucket policy if Amazon S3 considers the policy public. Existing bucket policies are not changed.

    Ignore public ACLs - Ignores public permissions granted by ACLs without deleting those ACLs. New public ACLs can still be stored, so they can become effective if this setting is later cleared.

    Restrict public buckets - When a bucket policy is public, limits access to AWS service principals and authorized users in the bucket owner's account. It also blocks cross-account access granted by that public policy, including grants to specific accounts.

    For most buckets, keep all four settings enabled. Block Public Access does not delete existing ACLs or bucket policies; removing a protection can make previously stored public permissions effective again.

  2. Choose the required settings, then click OK.

Related Articles

CS Browser 13.5.5 Freeware
Powered by Amazon Web Services and Rated by CNET Editors!
Social Connection
 
People like CS Browser!
People like us
Our customers say

"CS Browser is an invaluable tool to me as a web developer to easily manage my automated site backups" -Bob Kraft, Web Developer

"Just want to show my appreciation for a wonderful product. I use CS Browser a lot, it is a great tool." -Gideon Kuijten, Pro User

"Thank You Thank You Thank You for this tool. A must have for anyone using Amazon S3!" -Brian Cummiskey, USA

Related Products
RdpGuard
protects your Windows Server from RDP Brute-force Attacks.
CS Browser is developed by Netsdk Software FZE and is not affiliated with, endorsed by, or sponsored by Amazon or AWS. Amazon S3 and Amazon S3 Glacier are trademarks of Amazon.com, Inc. or its affiliates.
Copyright © 2008-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.  Mount Amazon S3 Bucket.  RDP brute-force protection.