Medium IAM

MFA should be enabled for all IAM users that have a console password

CIS

Description

Verifies that MFA is enabled for all IAM users with a console password.


Remediation

To enable MFA for IAM users with a console password, follow these steps:

Steps

  1. Sign in to the AWS Management Console with an account that has IAM permissions.
  2. Open the IAM console at https://console.aws.amazon.com/iam/.
  3. In the navigation pane, click on 'Users'.
  4. Choose the IAM user who has a console password and for whom you want to enable MFA.
  5. Under the 'Security credentials' tab, in the 'Assigned MFA device' section, click on 'Manage'.
  6. Choose the type of MFA device to assign and follow the on-screen instructions.
  7. Enter two consecutive MFA codes from the application to finalize setup.
  8. Confirm that the MFA device is successfully associated with the IAM user.

Compliance

CIS