Medium
Cognito
Regional
Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication
Description
Flags Amazon Cognito user pools whose threat protection is not activated in full function (ENFORCED) mode for custom authentication. Audit-only mode logs suspicious activity but does not block it.
Remediation
Configure threat protection to ENFORCED for custom authentication on every user pool.
Steps
- Open the Amazon Cognito console and select the user pool.
- Choose Authentication, then Threat protection.
- Activate threat protection and set Custom authentication enforcement mode to Full function.
- Save the changes.