Review IAM users’ password-change permissions

Provide an appropriate way for IAM users to change their own passwords when needed.

Description

Users without password-change permission depend on administrators to replace initial or exposed passwords. allow_users_to_change_password = false withholds the account-wide grant; a separate IAM policy can still permit a user to change their own password.

Potential impact

  • Exposed passwords can remain in use if no suitable change process exists.
  • Waiting for administrators can delay account recovery and incident response.

Remediation

Set allow_users_to_change_password = true to allow all IAM users. For selected users, grant appropriate iam:ChangePassword permission for their own password and iam:GetAccountPasswordPolicy. Retain MFA and password-strength requirements.

Examples

These examples compare the account-wide grant. Also review separate IAM policies and applicable permission limits.

Before

hcl
resource "aws_iam_account_password_policy" "example" {
  minimum_password_length        = 8
  require_lowercase_characters   = true
  require_numbers                = true
  require_uppercase_characters   = true
  require_symbols                = true
  allow_users_to_change_password = false
}

After

hcl
resource "aws_iam_account_password_policy" "example" {
  minimum_password_length        = 10
  require_lowercase_characters   = true
  require_numbers                = true
  require_uppercase_characters   = true
  require_symbols                = true
  allow_users_to_change_password = true
}

The revision grants self-service password changes through the account policy. The length also changes from 8 to 10 characters; choose the actual requirement according to the organization’s standard.

References