AWS Compare High-frequency comparison

Password Policy, MFA, Access Key, and Temporary Credentials

Password Policy, MFA, Access Key and Temporary Credentials

compareMFAAccess KeyIAM
Last organized

Separates password rules, additional authentication factors, long-term keys, and expiring credentials.

In one sentence

Password policy controls IAM user password rules, MFA adds an authentication factor, access keys sign API requests, and temporary credentials expire automatically.

Boundaries

Password policy applies to IAM user console passwords, not root passwords, access keys, or IAM Identity Center passwords. MFA strengthens authentication but grants no authorization; a policy condition may require an MFA context.

Long-term credentials contain an access key ID and secret access key and do not expire automatically. Temporary credentials add a session token and have an expiration. Prefer IAM Identity Center or federation for people and roles for workloads.

Console normally uses password plus MFA or an SSO session. CLI and SDK can use Identity Center, AssumeRole, workload roles, or access keys. aws configure stores profile settings but grants no permissions, and CloudShell cannot exceed the current console identity.

Never share or hard-code secrets. A leaked key must be revoked or rotated, with CloudTrail and the exposure scope investigated.

Safe rotation and modern identity choices

Rotate a long-term key by creating a replacement → updating and verifying every consumer → deactivating the old key → deleting it after confirming no failures. Revoke or rotate exposed secrets immediately and investigate CloudTrail and exposure scope; deleting a Git commit is insufficient.

PrincipalPreferred approach
Employees and administratorsIAM Identity Center / federation + MFA + temporary credentials
Workloads on AWSInstance profile, task role, execution role
Workloads outside AWSRoles Anywhere or OIDC/SAML federation
Legacy system without temporary-credential supportDedicated IAM user + least-privilege key + rotation and monitoring