---
title: >-
  IAM user with administrative permissions has console access without MFA in an
  account with a weak password policy
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > IAM user with administrative
  permissions has console access without MFA in an account with a weak password
  policy
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# IAM user with administrative permissions has console access without MFA in an account with a weak password policy

## Description{% #description %}

An IAM user with administrative permissions has console access enabled without MFA in an AWS account with a weak password policy. The weak password policy combined with the absence of MFA means an attacker who compromises the user's password can authenticate directly to the console with full administrative access. This allows unrestricted control over all AWS resources, including the ability to create or delete resources, modify security configurations, and access sensitive data.

## Remediation{% #remediation %}

1. Enable MFA for the IAM user by following the [AWS MFA documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable.html) and enforce strong password policies using the [IAM password policy settings](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_passwords_account-policy.html).
1. Apply the principle of least privilege by removing unnecessary administrative permissions and use permission boundaries to limit user capabilities.
