Medium
Cognito
Regional
Password policies for Cognito user pools should have strong configurations
Description
Flags Amazon Cognito user pools whose password policy does not meet the recommended baseline (8+ chars, requires upper/lower case, number, symbol, and a temporary password validity of no more than 7 days).
Remediation
Strengthen the user pool's password policy to meet the recommended baseline.
Steps
- Open the Amazon Cognito console and select the user pool.
- Choose Sign-in experience, then Edit.
- Under Password policy, set minimum length to at least 8 and require uppercase, lowercase, number, and symbol characters.
- Set the temporary password validity to no more than 7 days.
- Save the changes.