Hello Admin,
Thank you for posting your question on Microsoft Windows Forum!
Yes, AWS provides a supported way to enforce IMDSv2 and disable IMDSv1 access on existing EC2 instances using the AWS CLI. AWS documents that you can modify the instance metadata options of a running or stopped instance using the modify-instance-metadata-options command.
Before Enforcing IMDSv2
AWS recommends first verifying that your applications are no longer making IMDSv1 requests. The MetadataNoToken CloudWatch metric can be used to identify IMDSv1 usage. AWS advises requiring IMDSv2 only after this metric shows zero IMDSv1 calls.
Enforce IMDSv2 on an Existing Instance
Using PowerShell:
aws ec2 modify-instance-metadata-options </span>
--instance-id i-xxxxxxxxxxxxxxxxx </span>
--http-tokens required
When http-tokens is set to:
required
IMDSv2 becomes mandatory and IMDSv1 requests are no longer allowed.
Verify the Setting
Using PowerShell:
aws ec2 describe-instances </span>
--instance-ids i-xxxxxxxxxxxxxxxxx </span>
--query "Reservations[].Instances[].MetadataOptions"
AWS notes that when modifying a running instance, the change may initially show as:
pending
and later transition to:
applied
once the modification completes.
Apply to Multiple Instances
For multiple EC2 instances, you can apply the change in a loop:
Using PowerShell:
for id in $(aws ec2 describe-instances </span>
--query "Reservations[].Instances[].InstanceId" </span>
--output text)
do
aws ec2 modify-instance-metadata-options </span>
--instance-id $id </span>
--http-tokens required
done
Additional Recommendation
If this is a compliance requirement identified during a security audit, you may also want to prevent future instances from being launched with IMDSv1 enabled by reviewing your account-level EC2 metadata settings and deployment templates. AWS also supports IAM policies to control who can modify instance metadata options.
For official AWS guidance, please review:
- Modify instance metadata options for existing instances [docs.aws.amazon.com]
- AWS CLI modify-instance-metadata-options [docs.aws.amazon.com]
I hope this answer has brought you useful information. If so, please click on "Accept Answer" and consider upvoting it. Doing so helps other community members identify useful solutions to similar issues