Description
Users without password-change permission must rely on an administrator to replace an initial or exposed password. allow_pw_change: false does not grant that permission through the account policy; a separate IAM policy can allow users to change their own passwords.
Potential impact
- An exposed password may remain in use if there is no suitable change process.
- Waiting for administrative intervention can delay account recovery and incident response.
Remediation
- To allow all IAM users to change their passwords, set allow_pw_change: true or its alias allow_password_change: true. Use one consistent name for the option within a task.
- For selected users, grant appropriate iam:ChangePassword permission on their own password and iam:GetAccountPasswordPolicy. Check applicable denies, MFA and password-strength requirements.
Examples
These examples compare account-level password-change permission. Use a collection supporting amazon.aws.iam_password_policy or its community.aws redirect. Review the other policy values against organizational requirements.
Before
yaml
- name: Configure the password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: false
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
- name: Configure the password policy using an alias
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_password_change: false
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
After
yaml
- name: Configure the password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
Explanation:
- Before: The account policy does not grant users permission to change their own passwords. Check any separate IAM permissions as well.
- After: The account policy allows users to change their own passwords.