Review IAM user password-change permissions

Provide a way for IAM users to change their own passwords when needed.

Description

Users without password-change permission must rely on an administrator to replace an initial or exposed password. allow_pw_change: false does not grant that permission through the account policy; a separate IAM policy can allow users to change their own passwords.

Potential impact

  • An exposed password may remain in use if there is no suitable change process.
  • Waiting for administrative intervention can delay account recovery and incident response.

Remediation

  • To allow all IAM users to change their passwords, set allow_pw_change: true or its alias allow_password_change: true. Use one consistent name for the option within a task.
  • For selected users, grant appropriate iam:ChangePassword permission on their own password and iam:GetAccountPasswordPolicy. Check applicable denies, MFA and password-strength requirements.

Examples

These examples compare account-level password-change permission. Use a collection supporting amazon.aws.iam_password_policy or its community.aws redirect. Review the other policy values against organizational requirements.

Before

yaml
- name: Configure the password policy
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: false
    pw_max_age: 60
    pw_reuse_prevent: 5
    pw_expire: false

- name: Configure the password policy using an alias
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_password_change: false
    pw_max_age: 60
    pw_reuse_prevent: 5
    pw_expire: false

After

yaml
- name: Configure the password policy
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_max_age: 60
    pw_reuse_prevent: 5
    pw_expire: false

Explanation:

  • Before: The account policy does not grant users permission to change their own passwords. Check any separate IAM permissions as well.
  • After: The account policy allows users to change their own passwords.

References