Password policy should prevent password reuse

Description

IAM password policies can prevent the reuse of a given password by the same user. Datadog recommends that the password policy prevents the reuse of passwords to enhance security.

Preventing password reuse increases account resiliency against brute force login attempts by ensuring that users create unique passwords over time, which strengthens the security posture of the AWS account.

Remediation

For instructions on preventing password reuse in IAM password policies, refer to Managing an IAM User Password Policy.