Review IAM password expiration policy

Choose password expiration according to the organization’s authentication and recovery policy.

Description

IAM max_password_age controls console-password validity. Non-expiring passwords are a valid configuration, so absence of an expiration period does not itself make an account vulnerable. Where the organization requires expiration, the setting and user change process should meet that requirement.

Potential impact

  • Exposed passwords may remain usable without an effective replacement process.
  • Very short expiration periods or abrupt policy changes can disrupt legitimate sign-ins.

Remediation

If expiration is required, set max_password_age to 1–1095 days according to policy and prepare password-change and recovery procedures. Retain MFA and replace compromised passwords immediately instead of waiting for expiry. This policy does not expire access keys.

Examples

These examples compare password expiration. Applying a period immediately affects passwords already older than that period.

Before

hcl
resource "aws_iam_account_password_policy" "example" {
  minimum_password_length        = 8
  require_lowercase_characters   = true
  require_numbers                = true
  require_uppercase_characters   = true
  require_symbols                = true
  allow_users_to_change_password = true
}

After

hcl
resource "aws_iam_account_password_policy" "example" {
  minimum_password_length        = 8
  require_lowercase_characters   = true
  require_numbers                = true
  require_uppercase_characters   = true
  require_symbols                = true
  allow_users_to_change_password = true
  max_password_age               = 10
}

The first example has no expiration period; the second uses 10 days. Ten days illustrates the setting and is not a universal recommendation.

References