QuestionQ9

Security and Compliance

A company has an organization in AWS Organizations. It has configured AWS Single Sign-On (AWS SSO) to centrally manage access to the AWS accounts in that organization. A DevOps engineer must ensure that every user signs in using multi-factor authentication (MFA). Users must be able to manage their own MFA devices, and they must be prompted for MFA each time they sign in.

What should the DevOps engineer do to satisfy these requirements?

Explanation

AWS IAM Identity Center (formerly AWS SSO) always-on MFA requires users who have registered MFA devices to complete an MFA challenge every time they sign in. Configuring users without a registered device to register one at sign-in enables MFA self-enrollment, so users can manage their own devices while MFA is enforced. Context-aware MFA can omit a new MFA prompt for a trusted sign-in context.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!