Description
Do not create a login profile for an account that does not need console access, such as an automation-only user. Prefer federated sign-in and temporary credentials for people.
Potential impact
An unnecessary console password adds a credential to manage and another access path that phishing or a password leak could expose.
Remediation
Remove aws_iam_user_login_profile for users that do not need console access. Where IAM user sign-in is required, use MFA and an appropriate password policy.
Examples
The examples keep the IAM user and remove only its console login profile. Review existing sessions and other credentials separately.
Before
hcl
resource "aws_iam_user" "example" {
name = "example"
path = "/"
force_destroy = true
}
resource "aws_iam_user_login_profile" "example_login" {
user = aws_iam_user.example.name
pgp_key = "keybase:some_person_that_exists"
}
After
hcl
resource "aws_iam_user" "example" {
name = "example"
path = "/"
force_destroy = true
}