SecurityConfig / IamPasswordPolicyConfig

IAM password policy configuration

iamPasswordPolicy:
allowUsersToChangePassword: true
hardExpiry: false
requireUppercaseCharacters: true
requireLowercaseCharacters: true
requireSymbols: true
requireNumbers: true
minimumPasswordLength: 14
passwordReusePrevention: 24
maxPasswordAge: 90
interface IIamPasswordPolicyConfig {
    allowUsersToChangePassword: boolean;
    hardExpiry: boolean;
    maxPasswordAge: number;
    minimumPasswordLength: number;
    passwordReusePrevention: number;
    requireLowercaseCharacters: boolean;
    requireNumbers: boolean;
    requireSymbols: boolean;
    requireUppercaseCharacters: boolean;
}

Properties

allowUsersToChangePassword: boolean

Allows all IAM users in your account to use the AWS Management Console to change their own passwords.

true
hardExpiry: boolean

Prevents IAM users who are accessing the account via the AWS Management Console from setting a new console password after their password has expired. The IAM user cannot access the console until an administrator resets the password.

true
maxPasswordAge: number

The number of days that an IAM user password is valid.

Valid values are between 1 and 1095 days.

90
minimumPasswordLength: number

The minimum number of characters allowed in an IAM user password.

Note: If you do not specify a value for this parameter, then the operation uses the default value of 6.

14
passwordReusePrevention: number

Specifies the number of previous passwords that IAM users are prevented from reusing.

Note: If you do not specify a value for this parameter, then the operation uses the default value of 0. The result is that IAM users are not prevented from reusing previous passwords.

24
requireLowercaseCharacters: boolean

Specifies whether IAM user passwords must contain at least one lowercase character from the ISO basic Latin alphabet (a to z).

Note: If you do not specify a value for this parameter, then the operation uses the default value of false. The result is that passwords do not require at least one lowercase character.

true
requireNumbers: boolean

Specifies whether IAM user passwords must contain at least one numeric character (0 to 9).

Note: If you do not specify a value for this parameter, then the operation uses the default value of false. The result is that passwords do not require at least one numeric character.

true
requireSymbols: boolean

Specifies whether IAM user passwords must contain at least one of the following non-alphanumeric characters:

! @ # $ % ^ & * ( ) _ + - = [ ] { } | '

Note: If you do not specify a value for this parameter, then the operation uses the default value of false. The result is that passwords do not require at least one symbol character.

true
requireUppercaseCharacters: boolean

Specifies whether IAM user passwords must contain at least one uppercase character from the ISO basic Latin alphabet (A to Z).

Note: If you do not specify a value for this parameter, then the operation uses the default value of false. The result is that passwords do not require at least one uppercase character.

true