EC2 instance has no IAM instance profile

Severity
Medium
Service
EC2
Check ID
EC2_NO_INSTANCE_PROFILE

What this check finds

A running EC2 instance carries no IAM instance profile. Any AWS access it needs must therefore come from credentials placed on the instance — environment variables, a config file, or baked into an AMI. Those are long-lived, do not rotate, and travel with every snapshot and image made from the host. An instance profile issues short-lived credentials that rotate automatically and can be revoked centrally.

Passing looks like: EC2 instances use IAM instance profiles.

How to fix it

Create a least-privilege role for the workload and attach it: EC2 console → select instance → Actions → Security → Modify IAM role. Then remove any static keys from the instance and from the AMI it was built from.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to EC2 instance has no IAM instance profile
FrameworkControls
CIS AWS Foundations Benchmark v5.0.0
  • 1.17 Ensure IAM instance roles are used for AWS resource access from instances
NIST SP 800-53 Rev5 (Moderate)
  • AC-6 Least Privilege
  • IA-5 Authenticator Management
NIST Cybersecurity Framework 2.0
  • PR.AA-01 Identities and credentials are managed
  • PR.AA-05 Access permissions and authorizations are enforced with least privilege
ISO/IEC 27001:2022 Annex A
  • A.5.17 Authentication information
  • A.8.2 Privileged access rights

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More EC2 checks

All EC2 checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only