AWS accounts whose IAM password policy falls short of a strong baseline
What does ZopNight detect here?
The IAM account password policy governs every IAM user console password. ZopNight flags an account whose custom policy misses its baseline of at least 14 characters, all four character types, reuse prevention of 24 and a maximum password age of 90 days or less. An account with no custom policy returns `NoSuchEntity` and is not evaluated.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1523 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | policy recorded as non-compliant |
| Source | ZopNight |
| Permissions used | iam:GetAccountPasswordPolicy |
What the account password policy controls, and what it does not
Every IAM user who signs in to the console does so with a password governed by one account-wide policy. If you never set one, IAM applies the default password policy: a minimum of 8 characters, at least three of the four character types, and passwords that never expire. There is no protection against reusing an old password.
Two limits matter when reading this finding. The policy does not apply to the root user password, and it does not apply to access keys. It hardens console sign-in for IAM users and nothing else.
Reading your current policy
aws iam get-account-password-policyWhen no custom policy is defined, the command returns a NoSuchEntity error, which means the
default rules above are in force. Otherwise it prints fields such as MinimumPasswordLength,
RequireSymbols, RequireNumbers, RequireUppercaseCharacters, RequireLowercaseCharacters,
MaxPasswordAge and PasswordReusePrevention.
When the finding is raised
ZopNight evaluates the account password policy during discovery and stores a single verdict: compliant or not. A policy is compliant only when the minimum length is at least 14, all four character types are required, reuse prevention is at least 24 and a maximum password age of 90 days or less is set. A setting that is missing counts against the policy. The rule fires only when the verdict is explicitly “not compliant”. It does not read tags, and it raises one finding per account rather than one per user.
When the check has nothing to say
If the policy could not be evaluated, for example because the scanning role lacks
iam:GetAccountPasswordPolicy, no verdict is recorded and the rule stays silent. The same applies
to an account with no custom policy at all: NoSuchEntity produces no verdict, so an account still
on the AWS default policy is not flagged here. Check it with the command above.
Why there is no dollar figure
Password policy is a governance control, so the finding carries a $0 saving. The risk it addresses is credential guessing and reuse: a short, never-expiring, reusable password on an IAM user with console access is the easiest way into an account that has not moved people to federation.
Setting a policy that meets the baseline
- Decide on values. The recommended baseline is a 14-character minimum, all four character types, 90-day expiry and reuse prevention of 24, which is the maximum IAM allows.
- Apply them in one call. The operation does not support partial updates, so any setting you leave out reverts to its default:
aws iam update-account-password-policy \ --minimum-password-length 14 \ --require-symbols --require-numbers \ --require-uppercase-characters --require-lowercase-characters \ --max-password-age 90 --password-reuse-prevention 24 \ --allow-users-to-change-password- Pair the policy with MFA for every console user; see IAM User Without MFA Enabled.
- Longer term, move people to IAM Identity Center so fewer IAM user passwords exist at all.