Ensure IAM Passwords require at least 1 number

IAM allows for creating users directly with in the AWS console for end users to be allowed to interact with the various services that AWS offers. Password complexity should be enforced and this reason is why password length is important. For this reason it is considered a security best practice not keep using the same password. Ensuring that it is restricted will help you with CIS and NIST Compliance.

Audit & Remediation

  • Login into your AWS account
  • Navigate to the IAM service at: https://console.aws.amazon.com/iam
  • on the left panel, select Account settings then select the Set password policy button.



  • Under Set password policy select the Require at least one number.



  • Repeat the outlined steps for each AWS account that you have.
