Skip to content

Commit ef0056b

Browse files
authored
fix: Allow user to change own password when no MFA is present (#470)
1 parent 5fd612c commit ef0056b

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

modules/iam-group-with-policies/policies.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,8 @@ data "aws_iam_policy_document" "iam_self_management" {
167167
"iam:ListMFADevices",
168168
"iam:ListVirtualMFADevices",
169169
"iam:ResyncMFADevice",
170-
"sts:GetSessionToken"
170+
"sts:GetSessionToken",
171+
"iam:ChangePassword"
171172
]
172173
resources = ["*"]
173174

0 commit comments

Comments
 (0)