IAM user console password-reset policy needs review

Manage delivery of initial console passwords and require users to change them at sign-in.

Description

Without a password-change requirement, an IAM user with console access can continue using the initial password supplied by an administrator. Retaining a shared or exposed initial value can increase the risk of account misuse.

Do not add a LoginProfile to users who do not need console access. Changing a password does not rotate API access keys or replace MFA and least-privilege permissions.

Potential impact

  • Someone who knows the initial password may retain an opportunity to access the account.
  • Password sharing or reuse can weaken individual credential management.

Remediation

For IAM users needing console access, set LoginProfile.PasswordResetRequired to true and verify permission to change their own password. Deliver the initial value securely and confirm the change is completed. Apply MFA and a password policy, and prefer federation where appropriate.

Examples

InitialPassword is a per-user initial value meeting the account password policy. Supply it through an approved secret-input method such as a NoEcho parameter without a default, and do not expose it in Metadata or Outputs. Configure user permissions separately.

Before

yaml
Resources:
  MyUser:
    Type: AWS::IAM::User
    Properties:
      LoginProfile:
        Password: !Ref InitialPassword
        PasswordResetRequired: false

A password change is not required. Keeping the value outside the template does not replace a first-sign-in change policy.

After

yaml
Resources:
  MyUser:
    Type: AWS::IAM::User
    Properties:
      LoginProfile:
        Password: !Ref InitialPassword
        PasswordResetRequired: true

A password change is required at sign-in. Verify that the user has permission to perform the change and can complete the sign-in process.

References