Force IAM user to change password after first authentication.

0

To meet some PCI requirements, we need to force users to change their password after first authentication into the aws console. I have tried to search for information about how to do that in AWS, using IAM features, but was not able to find anything, is it possible?

Thanks

2 個答案
1
已接受的答案

When you create an IAM user there is a checkbox for User must create a new password at next sign-in which does what you want. As an administrator you can enforce that for the next login for existing users as well.

If you're operating in a multi-account environment or are using AWS Organizations then I'd strongly recommend using IAM Identity Center which gives you the ability to use a central identity provider. Then you can control password policies and other authentication requirements (such as MFA) centrally.

profile pictureAWS
專家
已回答 1 年前
profile pictureAWS
專家
已審閱 1 年前
1

When creating a User through the Console, you can specify that they need to change their password when they first log in:

screenshot of IAM user creation

If you are creating or updating your Users via the API/CLI, you call the CreateLoginProfile or UpdateLoginProfile APIs, which both support configuring the User to need to change their password when they first/next log in.

If you are using the CLI, the update command could look like this, for example:

aws iam update-login-profile --user-name james --password-reset-required
profile pictureAWS
專家
James_S
已回答 1 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南