Ensure that your Identity and Access Management (IAM) users are using a password policy that requires minimum 14 characters for passwords in order to enforce creating strong user passwords.
Enforcing IAM user passwords strength, pattern, and rotation is vital when it comes to maintaining the security of your Oracle Cloud Infrastructure (OCI) account. Having a strong password policy in use will significantly reduce the risk of password-guessing methods and brute-force attacks. The default IAM password policy does not enforce any element in a user password.
Audit
To determine if your password policy enforces a minimum length of 14 characters for IAM user passwords, perform the following operations:
Remediation / Resolution
To enforce a minimum length of 14 characters for your OCI IAM user passwords, perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Managing Password Policies
- Modifying the Custom Password Policy
- Oracle Cloud Infrastructure CLI Documentation
- group list
- authentication-policy get
- authentication-policy update