Ensure IAM user, group, or role do not have access to create or update login profiles (passwords) for IAM users

To prevent privilege escalation, you should use service control policies (SCPs) to prevent users in your accounts, except for IAM administrators or delegated admins, from using administrative IAM actions.