Review the IAM password minimum length

Set the minimum length of IAM users’ console passwords to meet your organization’s requirements.

Description

An IAM account password policy with a minimum length below your organization’s requirement can permit short, easily guessed passwords. Omitting minimumPasswordLength does not remove all length restrictions; check the effective policy and defaults.

This policy applies to IAM users’ console passwords, not root-user passwords or access keys. Changing the length requirement does not automatically replace existing passwords.

Potential impact

  • Allowing short, weak passwords can increase the risk of account compromise through guessing attacks.
  • Organizational password requirements may be applied inconsistently.

Remediation

Set minimumPasswordLength to your organization’s requirement and apply other authentication protections, including MFA. The changed length requirement takes effect at the next password change, so plan any necessary resets for existing users separately.

Examples

This comparison assumes an organizational minimum of 14 characters. That is the example’s requirement, not an AWS minimum that applies to every environment.

Before

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: aws:iam:AccountPasswordPolicy
    properties:
      minimumPasswordLength: 10

After

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: aws:iam:AccountPasswordPolicy
    properties:
      minimumPasswordLength: 14

The after-example requires at least 14 characters for new or changed passwords. It does not immediately change passwords already in use.

References