Skip to content

UpdateLoginProfile

AWS

UpdateLoginProfile

service: AWS - IAM
techniques:

Event

Updates an existing IAM login profile. Password and passwordResetRequired are optional request fields, so a reset-requirement change is not by itself proof of a password replacement. This is distinct from a user changing their own password with ChangePassword.

Security Context

An unauthorized password replacement can enable account manipulation (T1098) or deny the legitimate user password-based access (T1531). Approved password resets are routine; an event changing only the reset requirement does not establish either outcome. Neither operation grants permissions, removes MFA devices, or changes access keys. A password setting is not proof of a successful console sign-in.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: UpdateLoginProfile. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
userNameTarget IAM user, distinct from the calling identity.
passwordResetRequiredWhether the user must change the password at next sign-in; false does not bypass MFA.
passwordSensitive input; do not expect a readable password in CloudTrail or infer its value from a redaction.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Check the approved onboarding or reset record and confirm exactly which settings changed. Account password-policy requirements and operation errors matter.
  3. Inspect MFA configuration and existing permissions separately. Do not assume this event disables MFA, revokes API keys, or invalidates every existing session.
  4. Correlate ConsoleLogin outcomes and subsequent user activity; investigate DeactivateMFADevice only if separate evidence shows it occurred.

Sample Event

Synthetic scenario. Draco submits passwordResetRequired false for hermione. No password field is shown, so this example illustrates a reset-requirement update and does not establish a password reset or account takeover.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:54:42Z",
"eventSource": "iam.amazonaws.com",
"eventName": "UpdateLoginProfile",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "hermione",
"passwordResetRequired": false
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000111010000",
"eventID": "90000000-0000-4000-8000-000111010001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Impact

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.