Remediation
From Consoleβ
Perform the following to manage Unused Password (IAM user console access):
- Login to the AWS Management Console.
- Click
Services. - Click
IAM. - Click on
Users. - Click on
Security Credentials. - Select user whose
Console last sign-inis greater than45days. - Click
Security credentials. - In section
Sign-in credentials,Console passwordclickManage. - Under Console Access select
Disable. - Click
Apply.
Perform the following to deactivate Access Keys:
- Login to the AWS Management Console.
- Click
Services. - Click
IAM. - Click on
Users. - Click on
Security Credentials. - Select any access keys that are over 45 days old and that have been used and click on
Make Inactive. - Select any access keys that are over 45 days old and that have not been used and click the X to
Delete.