UpdateLoginProfile
UpdateLoginProfile
Event
Updates an existing IAM login profile. Password and passwordResetRequired are optional request fields, so a reset-requirement change is not by itself proof of a password replacement. This is distinct from a user changing their own password with ChangePassword.
Security Context
An unauthorized password replacement can enable account manipulation (T1098) or deny the legitimate user password-based access (T1531). Approved password resets are routine; an event changing only the reset requirement does not establish either outcome. Neither operation grants permissions, removes MFA devices, or changes access keys. A password setting is not proof of a successful console sign-in.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: UpdateLoginProfile. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
userName | Target IAM user, distinct from the calling identity. |
passwordResetRequired | Whether the user must change the password at next sign-in; false does not bypass MFA. |
password | Sensitive input; do not expect a readable password in CloudTrail or infer its value from a redaction. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Check the approved onboarding or reset record and confirm exactly which settings changed. Account password-policy requirements and operation errors matter.
- Inspect MFA configuration and existing permissions separately. Do not assume this event disables MFA, revokes API keys, or invalidates every existing session.
- Correlate ConsoleLogin outcomes and subsequent user activity; investigate DeactivateMFADevice only if separate evidence shows it occurred.
Sample Event
Synthetic scenario. Draco submits passwordResetRequired false for hermione. No password field is shown, so this example illustrates a reset-requirement update and does not establish a password reset or account takeover.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:54:42Z", "eventSource": "iam.amazonaws.com", "eventName": "UpdateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "hermione", "passwordResetRequired": false }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000111010000", "eventID": "90000000-0000-4000-8000-000111010001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Impact
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....