Description
Without reuse prevention, or with less history than the organization requires, users can return to old passwords. Reusing a compromised password can undo the benefit of changing it. Password history limits recent reuse; it does not replace MFA or incident response.
Potential impact
- A previously exposed password may be used again.
- Repeatedly returning to the same secret can weaken account protection after a password change.
Remediation
Set password_reuse_prevention to the required history depth. AWS supports preventing reuse of 1–24 previous passwords. Combine it with sufficient length, MFA, and prompt replacement after compromise.
Examples
These examples compare password-history settings. Review the other length and character requirements against the organization’s policy as well.
Before
resource "aws_iam_account_password_policy" "example" {
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
password_reuse_prevention = 20
}
After
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 8
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
password_reuse_prevention = 24
}
The first setting already prevents reuse of the previous 20 passwords. The second increases that history to 24; a value of 20 does not mean reuse prevention is absent.