Description
Without IAM password reuse prevention, or with less history than the organization requires, users can return to previous passwords. Reusing an exposed password can undo the benefit of changing it. History checks restrict recent passwords; they do not detect similar strings or passwords used by other services.
Potential impact
- A previously exposed password can be reused.
- Repeatedly returning to the same secret can weaken account protection despite password changes.
Remediation
- Set pw_reuse_prevent or a supported alias to the required history count. AWS supports preventing reuse of 1 to 24 previous passwords; 0 disables this restriction.
- Combine this with sufficient length, MFA and immediate replacement of exposed passwords. The setting applies to IAM console passwords and does not rotate access keys.
Examples
password_reuse_prevent and prevent_reuse are aliases for pw_reuse_prevent. Use one name in each task. The module defaults to 0 when omitted; these examples compare history settings only.
Before
yaml
- name: Configure the IAM password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
pw_expire: false
- name: Configure a second IAM password policy example
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
password_reuse_prevent: 0
pw_expire: false
After
yaml
- name: Configure the IAM password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
Explanation:
- Before: Omitting the value or setting 0 leaves password-history reuse restrictions disabled.
- After: Reuse of the five most recent passwords is restricted. Select the required history count according to organizational standards.