Review IAM password reuse prevention

Set the required password history so changes cannot simply return to earlier passwords.

Description

Without IAM password reuse prevention, or with less history than the organization requires, users can return to previous passwords. Reusing an exposed password can undo the benefit of changing it. History checks restrict recent passwords; they do not detect similar strings or passwords used by other services.

Potential impact

  • A previously exposed password can be reused.
  • Repeatedly returning to the same secret can weaken account protection despite password changes.

Remediation

  • Set pw_reuse_prevent or a supported alias to the required history count. AWS supports preventing reuse of 1 to 24 previous passwords; 0 disables this restriction.
  • Combine this with sufficient length, MFA and immediate replacement of exposed passwords. The setting applies to IAM console passwords and does not rotate access keys.

Examples

password_reuse_prevent and prevent_reuse are aliases for pw_reuse_prevent. Use one name in each task. The module defaults to 0 when omitted; these examples compare history settings only.

Before

yaml
- name: Configure the IAM password policy
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_max_age: 60
    pw_expire: false

- name: Configure a second IAM password policy example
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_max_age: 60
    password_reuse_prevent: 0
    pw_expire: false

After

yaml
- name: Configure the IAM password policy
  community.aws.iam_password_policy:
    state: present
    min_pw_length: 8
    require_symbols: false
    require_numbers: true
    require_uppercase: true
    require_lowercase: true
    allow_pw_change: true
    pw_max_age: 60
    pw_reuse_prevent: 5
    pw_expire: false

Explanation:

  • Before: Omitting the value or setting 0 leaves password-history reuse restrictions disabled.
  • After: Reuse of the five most recent passwords is restricted. Select the required history count according to organizational standards.

References