Review IAM password expiration policy

Choose password expiration and duration according to authentication and recovery requirements.

Description

pw_max_age sets the maximum age of IAM console passwords; 0 validly disables automatic expiration. If an organization requires expiration, the effective policy and user change process must meet that requirement. Password expiration does not expire access keys.

Potential impact

  • An exposed password may remain usable without an appropriate replacement process.
  • An excessively short period or abrupt policy change can disrupt legitimate sign-ins.

Remediation

  • If expiration is required, set pw_max_age or its alias password_max_age to an organizationally appropriate value from 1 to 1095 days, and prepare password-change and recovery procedures.
  • Maintain MFA and replace exposed passwords immediately rather than waiting for expiration. pw_expire separately controls whether users can change an expired password themselves.

Examples

The before tasks are alternatives with an omitted maximum age or 180 days. The module defaults an omitted pw_max_age to 0. Applying expiration also affects passwords already older than the selected period.

Before

yaml
- name: Configure the IAM password policy
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_reuse_prevent: 5
    pw_expire: false

- name: Configure a second IAM password policy example
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_max_age: 180
    pw_reuse_prevent: 5
    pw_expire: false

After

yaml
- name: Configure the IAM password policy
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_max_age: 20
    pw_reuse_prevent: 5
    pw_expire: false

Explanation:

  • Before: The first task does not enable automatic expiration, and the second uses 180 days. Suitability depends on organizational policy.
  • After: The maximum age is 20 days. This is illustrative, not a universal recommendation. pw_expire: false does not remove that expiration period.

References