Skip to main content
compliance · aws

AWS accounts whose IAM password policy falls short of a strong baseline

rule IDs covered
1
severity
medium
resource types
all

What does ZopNight detect here?

The IAM account password policy governs every IAM user console password. ZopNight flags an account whose custom policy misses its baseline of at least 14 characters, all four character types, reuse prevention of 24 and a maximum password age of 90 days or less. An account with no custom policy returns `NoSuchEntity` and is not evaluated.

Signal and threshold

How ZopNight evaluates AWS accounts whose IAM password policy falls short of a strong baseline.
Field Value
Rule IDsRC-1523
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdpolicy recorded as non-compliant
SourceZopNight
Permissions usediam:GetAccountPasswordPolicy

What the account password policy controls, and what it does not

Every IAM user who signs in to the console does so with a password governed by one account-wide policy. If you never set one, IAM applies the default password policy: a minimum of 8 characters, at least three of the four character types, and passwords that never expire. There is no protection against reusing an old password.

Two limits matter when reading this finding. The policy does not apply to the root user password, and it does not apply to access keys. It hardens console sign-in for IAM users and nothing else.

Reading your current policy

Terminal window
aws iam get-account-password-policy

When no custom policy is defined, the command returns a NoSuchEntity error, which means the default rules above are in force. Otherwise it prints fields such as MinimumPasswordLength, RequireSymbols, RequireNumbers, RequireUppercaseCharacters, RequireLowercaseCharacters, MaxPasswordAge and PasswordReusePrevention.

When the finding is raised

ZopNight evaluates the account password policy during discovery and stores a single verdict: compliant or not. A policy is compliant only when the minimum length is at least 14, all four character types are required, reuse prevention is at least 24 and a maximum password age of 90 days or less is set. A setting that is missing counts against the policy. The rule fires only when the verdict is explicitly “not compliant”. It does not read tags, and it raises one finding per account rather than one per user.

When the check has nothing to say

If the policy could not be evaluated, for example because the scanning role lacks iam:GetAccountPasswordPolicy, no verdict is recorded and the rule stays silent. The same applies to an account with no custom policy at all: NoSuchEntity produces no verdict, so an account still on the AWS default policy is not flagged here. Check it with the command above.

Why there is no dollar figure

Password policy is a governance control, so the finding carries a $0 saving. The risk it addresses is credential guessing and reuse: a short, never-expiring, reusable password on an IAM user with console access is the easiest way into an account that has not moved people to federation.

Setting a policy that meets the baseline

  1. Decide on values. The recommended baseline is a 14-character minimum, all four character types, 90-day expiry and reuse prevention of 24, which is the maximum IAM allows.
  2. Apply them in one call. The operation does not support partial updates, so any setting you leave out reverts to its default:
Terminal window
aws iam update-account-password-policy \
--minimum-password-length 14 \
--require-symbols --require-numbers \
--require-uppercase-characters --require-lowercase-characters \
--max-password-age 90 --password-reuse-prevention 24 \
--allow-users-to-change-password
  1. Pair the policy with MFA for every console user; see IAM User Without MFA Enabled.
  2. Longer term, move people to IAM Identity Center so fewer IAM user passwords exist at all.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·