AWS_IAM_30

Ensure there are no Inactive IAM Console User

Description

Identify any inactive IAM users, and disable their access as an extra security measure for protecting your AWS resources against unauthorized access. An IAM user is marked as inactive when is not being used for a specified period of time.

Remediation

1. Sign in to the AWS Management Console.

2. Navigate to IAM dashboard.

3. In the left navigation panel, choose Users.

4. Click on the inactive IAM user name to access the user configuration page.

5. Inside the Sign-In Credentials section, click Manage Password to access the user password management page.

6. On the Manage Password page, select Remove existing password to disable password-based access for the selected user.

7. Click Apply to submit the changes. The IAM user access to the AWS resources is now disabled.

Service

IAM

Severity

Medium

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!