IAM user has console access

Remove unnecessary IAM user console access.

Description

Do not create a login profile for an account that does not need console access, such as an automation-only user. Prefer federated sign-in and temporary credentials for people.

Potential impact

An unnecessary console password adds a credential to manage and another access path that phishing or a password leak could expose.

Remediation

Remove aws_iam_user_login_profile for users that do not need console access. Where IAM user sign-in is required, use MFA and an appropriate password policy.

Examples

The examples keep the IAM user and remove only its console login profile. Review existing sessions and other credentials separately.

Before

hcl
resource "aws_iam_user" "example" {
  name          = "example"
  path          = "/"
  force_destroy = true
}

resource "aws_iam_user_login_profile" "example_login" {
  user    = aws_iam_user.example.name
  pgp_key = "keybase:some_person_that_exists"
}

After

hcl
resource "aws_iam_user" "example" {
  name          = "example"
  path          = "/"
  force_destroy = true
}

References