QuestionQ35

Identity and Access Management

An AWS account administrator created an IAM group and attached the following managed policy to require every individual user to authenticate using multi-factor authentication:

Question Image

After the policy was implemented, the administrator receives reports that users cannot perform Amazon EC2 commands through the AWS CLI.

What should the administrator do to resolve this issue while continuing to enforce multi-factor authentication?

Explanation

Long-term IAM user access keys do not include MFA context, so the explicit deny blocks EC2 API calls. Users should call AWS STS get-session-token with their MFA device --serial-number and current --token-code, then use the returned temporary credentials for API or CLI calls. Those credentials include MFA context and can satisfy policies that require MFA for individual API operations.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!