Description
Users without password-change permission depend on administrators to replace initial or exposed passwords. allow_users_to_change_password = false withholds the account-wide grant; a separate IAM policy can still permit a user to change their own password.
Potential impact
- Exposed passwords can remain in use if no suitable change process exists.
- Waiting for administrators can delay account recovery and incident response.
Remediation
Set allow_users_to_change_password = true to allow all IAM users. For selected users, grant appropriate iam:ChangePassword permission for their own password and iam:GetAccountPasswordPolicy. Retain MFA and password-strength requirements.
Examples
These examples compare the account-wide grant. Also review separate IAM policies and applicable permission limits.
Before
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 8
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = false
}
After
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 10
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
}
The revision grants self-service password changes through the account policy. The length also changes from 8 to 10 characters; choose the actual requirement according to the organization’s standard.