Access All Buckets Without Delete Access

AWS September 19, 2026 23 Views 2 min read
Access All Buckets Without Delete Access

AWS S3: Access All Buckets Without Delete Access

This tutorial shows how to give an IAM user access to all S3 buckets in the AWS account for listing, reading and uploading objects, while preventing delete operations.

What the Policy Allows

  • View all S3 buckets
  • List objects in all buckets
  • Download and read objects
  • Upload and overwrite objects
  • View object versions
  • Use common S3 console functions

What the Policy Blocks

  • Delete an S3 bucket
  • Delete an object
  • Delete an object version
  • Abort a multipart upload

IAM Policy

Use this identity-based policy:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "S3ConsoleAccess",
            "Effect": "Allow",
            "Action": [
                "s3:ListAllMyBuckets",
                "s3:GetAccountPublicAccessBlock",
                "s3:GetBucketAcl",
                "s3:GetBucketLocation",
                "s3:GetBucketPolicyStatus",
                "s3:GetBucketPublicAccessBlock",
                "s3:ListAccessPoints"
            ],
            "Resource": "*"
        },
        {
            "Sid": "S3BucketReadWrite",
            "Effect": "Allow",
            "Action": [
                "s3:ListBucket",
                "s3:ListBucketVersions",
                "s3:ListBucketMultipartUploads"
            ],
            "Resource": "arn:aws:s3:::*"
        },
        {
            "Sid": "S3ObjectReadWrite",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:GetObjectVersion",
                "s3:GetObjectAcl",
                "s3:GetObjectTagging",
                "s3:PutObject",
                "s3:PutObjectAcl",
                "s3:PutObjectTagging",
                "s3:ListMultipartUploadParts"
            ],
            "Resource": "arn:aws:s3:::*/*"
        },
        {
            "Sid": "ExplicitlyDenyBucketDelete",
            "Effect": "Deny",
            "Action": [
                "s3:DeleteBucket"
            ],
            "Resource": "arn:aws:s3:::*"
        },
        {
            "Sid": "ExplicitlyDenyObjectDelete",
            "Effect": "Deny",
            "Action": [
                "s3:DeleteObject",
                "s3:DeleteObjectVersion",
                "s3:AbortMultipartUpload"
            ],
            "Resource": "arn:aws:s3:::*/*"
        }
    ]
}

How to Add the Policy

Open AWS Console → IAM → Users → Your User → Permissions → Add permissions → Create inline policy.

Select the JSON editor, paste the policy, review it, and save it.

Test the Access

List all buckets:

aws s3 ls

List objects:

aws s3 ls s3://YOUR-BUCKET-NAME/

Upload an object:

aws s3 cp test.txt s3://YOUR-BUCKET-NAME/test.txt

Download an object:

aws s3 cp s3://YOUR-BUCKET-NAME/test.txt .

Test delete access:

aws s3 rm s3://YOUR-BUCKET-NAME/test.txt

The delete command should return AccessDenied.

Important

PutObject allows overwriting an existing object with the same key. This policy prevents deletion, but it does not make objects immutable.

For common S3 console access, AWS documents permissions such as ListAllMyBuckets, GetBucketLocation, GetBucketAcl, GetBucketPolicyStatus, GetBucketPublicAccessBlock, GetAccountPublicAccessBlock and ListAccessPoints.

Suggested category: AWS

Discussion (0)