## TL;DR
IAM Identity Center lets you enforce MFA for everyone who signs in through it, in one place. Turn on MFA enforcement in the Identity Center settings, pick the allowed authenticator types, and require it at every sign-in. Then verify that no user can get in without it.

## The query
```
how to enforce MFA with AWS IAM Identity Center
```

## Use this when
- You manage workforce access to AWS and want MFA required, not optional
- An audit flagged accounts with console access and no MFA
- You are consolidating access through Identity Center and want one enforcement point
- You need to prove MFA coverage for compliance

## Not for
- The AWS root user; that gets MFA in the account settings, separately
- Federating through an external IdP; enforce MFA there instead
- Programmatic access keys; use short-lived credentials and permission boundaries for those

## Steps
1. Open IAM Identity Center settings. Go to the Identity Center console in your management region and find the MFA configuration section. Expected output: the current MFA settings visible, enforcement off or partial.
2. Turn on MFA enforcement. Set it to require MFA for every sign-in, not just prompt users to set it up. Expected output: the setting shows MFA required for all users.
3. Choose allowed authenticator types. Enable authenticator apps and security keys; decide whether you still allow SMS given its weaknesses. Expected output: a documented list of approved MFA methods.
4. Set session duration sensibly. Shorter sessions mean stolen session tokens expire faster; balance against user friction. Expected output: session length set and documented.
5. Test with a real user account. Sign in as a non-admin user and confirm MFA is demanded before any AWS access is granted, including users who never set up MFA before. Expected output: sign-in without MFA is impossible, new users are forced through enrollment.
6. Audit regularly. Pull the list of users and check MFA registration status; remove stale users who never enrolled. Expected output: 100 percent of active users have MFA registered, stale accounts disabled.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_yCzRKhTabzWJaDcEHOyEpw
