View a markdown version of this page

ACCT.05 Require multi-factor authentication to log in - AWS Prescriptive Guidance

ACCT.05 Require multi-factor authentication to log in

With multi-factor authentication (MFA), users have a device that generates a response to an authentication challenge. Each user's credentials and device-generated response are required to complete the sign-in process. Enable MFA for AWS account access, especially for long-term credentials such as the account root user and IAM users.

To set up MFA for the root user

  1. Sign in to the AWS Management Console.

  2. Choose your account name, and then choose Security credentials.

  3. On the Security credentials page, under Multi-factor authentication (MFA), choose Assign MFA device.

  4. Follow the steps to configure your MFA device. For more information, see Multi-factor authentication for AWS account root user in the IAM documentation.

To set up MFA in IAM Identity Center

  1. See Enable MFA in the IAM Identity Center documentation.

To set up MFA for your own IAM user

  1. Sign in to the IAM console.

  2. Choose your user name, and then choose Security credentials.

  3. On the Security credentials tab, under Multi-factor authentication (MFA), choose Assign MFA device.

  4. Follow the steps to configure your MFA device. For more information, see AWS Multi-Factor Authentication in IAM in the IAM documentation.

To set up MFA for other IAM users

  1. Sign in to the IAM console.

  2. In the navigation pane, choose Users.

  3. Choose the name of the user for whom you want to enable MFA, and then choose the Security credentials tab.

  4. Under Multi-factor authentication (MFA), choose Assign MFA device.

  5. Follow the steps to configure the MFA device. For more information, see AWS Multi-Factor Authentication in IAM in the IAM documentation.