スキップしてコンテンツを表示

IAM Password Policies

0

We can apply password Policies for all users in an AWS Account. So is it possible for doing the same for cross-account or deploy password policies in a **organization ** from the head account of the organization.

質問済み 1年前267ビュー
2回答
3
承認された回答

No I am afraid not. Each account has its own IAM password policy.

You need to configure the policy in every account. If using IaC, you can define the password policy on account creation etc or take ownership of the password policy via IaC and define it.

エキスパート
回答済み 1年前
エキスパート
レビュー済み 1年前
1

Hello,

I'd also add to the above the following considerations:

  • After deploying the password policy, consider implementing an SCP to prevent member accounts from modifying their IAM password policies
  • For enhanced security, consider using AWS Single Sign-On (SSO) instead of IAM users for account access
  • You could also use AWS Config Rules with SSM auto-remediation documents to ensure ongoing compliance with the password policy

You can check this lab on updating the password policy for all IAM users across all AWS accounts: https://github.com/aws-samples/devlab-iam-password-policy

AWS
回答済み 1年前
エキスパート
レビュー済み 1年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

関連するコンテンツ