Medium Cognito Regional

Cognito user pools should have threat protection activated with full function enforcement mode for custom authentication

Description

Flags Amazon Cognito user pools whose threat protection is not activated in full function (ENFORCED) mode for custom authentication. Audit-only mode logs suspicious activity but does not block it.


Remediation

Configure threat protection to ENFORCED for custom authentication on every user pool.

Steps

  1. Open the Amazon Cognito console and select the user pool.
  2. Choose Authentication, then Threat protection.
  3. Activate threat protection and set Custom authentication enforcement mode to Full function.
  4. Save the changes.