๐ก๏ธ AWS Account does not have an IAM Password Policy๐ข
- Contextual name: ๐ก๏ธ Account does not have an IAM Password Policy๐ข
- ID:
/ce/ca/aws/iam/password-policy - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Similar Policiesโ
- Cloud Conformity: IAM Password Policy
Descriptionโ
Descriptionโ
This policy identifies AWS Accounts that do not have an IAM password policy configured.
A strong password policy helps enforce requirements such as minimum password length, expiration period, and complexity rules for IAM users.
Rationaleโ
IAM password policies enable administrators to enforce password strength and complexity for users signing in to the AWS Management Console. Without a password policy, users may create weak passwords that are easily guessed or compromised, increasing the risk of unauthorized access to your AWS environment.
Auditโ
This policy flags an AWS Account as
INCOMPLIANTif there is no related AWS IAM Password Policy.Referencesโ
Remediationโ
Remediationโ
Configure an IAM Password Policyโ
Set a strong password policy to enforce minimum length, complexity, expiration, and password reuse restrictions for IAM users.
From Consoleโ
Sign in to the AWS Management Console with permissions to manage IAM account settings.
Navigate to the IAM service.
In the left navigation pane, select Account Settings.
In the Password policy section, choose Change password policy and configure the following (as an example):
- Enforce minimum password length: Set to 14 characters.
- Require at least one uppercase letter (A-Z).
- Require at least one lowercase letter (a-z).
- Require at least one number.
- Require at least one non-alphanumeric character (e.g., ! @ # $ % ^ & *).
- Enable password expiration: Set Expire passwords in โค 90 days.
- Prevent password reuse: Remember 24 previous passwords.
Click Save changes to apply the policy.
From Command Lineโ
Run the following AWS CLI command to configure the password policy:
... see more