Can I change the password policy for the SSO identity store?

1

We just had a pen test completed and one of the items was our password policy. I was looking at changing it, and I found this page: https://docs.aws.amazon.com/singlesignon/latest/userguide/password-requirements.html. It describes the password policy for the SSO identity store (which we are using), but not how to change the policy. Is it possible to change a password policy for the SSO identity store?

Thanks!

1개 답변
1

Currently there is no way to change the password policy when using AWS SSO as your identity source. This limitation applies only to users created in the AWS SSO identity store. If you have configured an identity source other than AWS SSO for authentication, such as Active Directory or an external identity provider, the password policies for your users are defined and enforced in those systems, not in AWS SSO and can be customized within those systems.

The product team is aware of the feature request. If you happen to work with an account manager at AWS you can have them or the solutions architect add your customer influence to the existing request. Features are added and worked based on the amount of customer influence a feature has.

AWS
AWSJoe
답변함 2년 전
  • Is this feature planned? PCI-DSS 4.0 (requirements 8.3.6 and 8.3.7) mandates 12 characters passwords, and that the last 4 passwords cannot be reused.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠