Review IAM password reuse prevention

Set the required password-history depth to prevent reuse when users change passwords.

Description

Without reuse prevention, or with less history than the organization requires, users can return to old passwords. Reusing a compromised password can undo the benefit of changing it. Password history limits recent reuse; it does not replace MFA or incident response.

Potential impact

  • A previously exposed password may be used again.
  • Repeatedly returning to the same secret can weaken account protection after a password change.

Remediation

Set password_reuse_prevention to the required history depth. AWS supports preventing reuse of 1–24 previous passwords. Combine it with sufficient length, MFA, and prompt replacement after compromise.

Examples

These examples compare password-history settings. Review the other length and character requirements against the organization’s policy as well.

Before

hcl
resource "aws_iam_account_password_policy" "example" {
  require_lowercase_characters   = true
  require_numbers                = true
  require_uppercase_characters   = true
  require_symbols                = true
  allow_users_to_change_password = true
  password_reuse_prevention      = 20
}

After

hcl
resource "aws_iam_account_password_policy" "example" {
  minimum_password_length        = 8
  require_lowercase_characters   = true
  require_numbers                = true
  require_uppercase_characters   = true
  require_symbols                = true
  allow_users_to_change_password = true
  password_reuse_prevention      = 24
}

The first setting already prevents reuse of the previous 20 passwords. The second increases that history to 24; a value of 20 does not mean reuse prevention is absent.

References