how to enforce MFA with AWS IAM Identity Center
Shows how to require MFA in AWS IAM Identity Center so every sign-in needs a second factor. Use this when hardening workforce access to AWS and you want MFA enforced centrally, not left to individual users. Not for root account MFA or for third-party SSO setups.
TL;DR
IAM Identity Center lets you enforce MFA for everyone who signs in through it, in one place. Turn on MFA enforcement in the Identity Center settings, pick the allowed authenticator types, and require it at every sign-in. Then verify that no user can get in without it.
The query
how to enforce MFA with AWS IAM Identity CenterUse this when
- You manage workforce access to AWS and want MFA required, not optional
- An audit flagged accounts with console access and no MFA
- You are consolidating access through Identity Center and want one enforcement point
- You need to prove MFA coverage for compliance
Not for
- The AWS root user; that gets MFA in the account settings, separately
- Federating through an external IdP; enforce MFA there instead
- Programmatic access keys; use short-lived credentials and permission boundaries for those
Steps
- Open IAM Identity Center settings. Go to the Identity Center console in your management region and find the MFA configuration section. Expected output: the current MFA settings visible, enforcement off or partial.
- Turn on MFA enforcement. Set it to require MFA for every sign-in, not just prompt users to set it up. Expected output: the setting shows MFA required for all users.
- Choose allowed authenticator types. Enable authenticator apps and security keys; decide whether you still allow SMS given its weaknesses. Expected output: a documented list of approved MFA methods.
- Set session duration sensibly. Shorter sessions mean stolen session tokens expire faster; balance against user friction. Expected output: session length set and documented.
- Test with a real user account. Sign in as a non-admin user and confirm MFA is demanded before any AWS access is granted, including users who never set up MFA before. Expected output: sign-in without MFA is impossible, new users are forced through enrollment.
- Audit regularly. Pull the list of users and check MFA registration status; remove stale users who never enrolled. Expected output: 100 percent of active users have MFA registered, stale accounts disabled.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_yCzRKhTabzWJaDcEHOyEpw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.