Description
IAM max_password_age controls console-password validity. Non-expiring passwords are a valid configuration, so absence of an expiration period does not itself make an account vulnerable. Where the organization requires expiration, the setting and user change process should meet that requirement.
Potential impact
- Exposed passwords may remain usable without an effective replacement process.
- Very short expiration periods or abrupt policy changes can disrupt legitimate sign-ins.
Remediation
If expiration is required, set max_password_age to 1–1095 days according to policy and prepare password-change and recovery procedures. Retain MFA and replace compromised passwords immediately instead of waiting for expiry. This policy does not expire access keys.
Examples
These examples compare password expiration. Applying a period immediately affects passwords already older than that period.
Before
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 8
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
}
After
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 8
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
max_password_age = 10
}
The first example has no expiration period; the second uses 10 days. Ten days illustrates the setting and is not a universal recommendation.