Remediation
From Consoleโ
Perform the following to manage unused passwords (IAM user console access):
- Log in to the AWS Management Console.
- Click
Services. - Click
IAM. - Click on
Users. - Click on
Security Credentials. - Select a user whose
Console last sign-inis greater than45days. - Click
Security credentials. - In the
Sign-in credentialssection, forConsole password, clickManage. - Under
Console Access, selectDisable. - Click
Apply.
Perform the following to deactivate Access Keys:
- Log in to the AWS Management Console.
- Click
Services. - Click
IAM. - Click on
Users. - Click on
Security Credentials. - Select any access keys that are over 45 days old and that have been used and click on
Make Inactive. - Select any access keys that are over 45 days old and that have not been used and click the X to
Delete.