If you can create or reset credentials on a more privileged principal, you become that principal without touching its policies. Two primitives: programmatic access keys, and console login profiles.
Paths#
- CreateAccessKey: mint a second set of long-term keys for a privileged user.
- CreateLoginProfile: set a console password on a user that has none.
- UpdateLoginProfile: reset the console password of a privileged user.