Description
An IAM account password policy with a minimum length below your organization’s requirement can permit short, easily guessed passwords. Omitting minimumPasswordLength does not remove all length restrictions; check the effective policy and defaults.
This policy applies to IAM users’ console passwords, not root-user passwords or access keys. Changing the length requirement does not automatically replace existing passwords.
Potential impact
- Allowing short, weak passwords can increase the risk of account compromise through guessing attacks.
- Organizational password requirements may be applied inconsistently.
Remediation
Set minimumPasswordLength to your organization’s requirement and apply other authentication protections, including MFA. The changed length requirement takes effect at the next password change, so plan any necessary resets for existing users separately.
Examples
This comparison assumes an organizational minimum of 14 characters. That is the example’s requirement, not an AWS minimum that applies to every environment.
Before
name: aws-eks
runtime: yaml
resources:
example:
type: aws:iam:AccountPasswordPolicy
properties:
minimumPasswordLength: 10
After
name: aws-eks
runtime: yaml
resources:
example:
type: aws:iam:AccountPasswordPolicy
properties:
minimumPasswordLength: 14
The after-example requires at least 14 characters for new or changed passwords. It does not immediately change passwords already in use.