내용으로 건너뛰기

Allowing multiple MFA devices for S3 MFADelete?

0

In looking here regarding enabling MFA deletion on an S3 bucket, and checking the AWS CLI v2 docs on the subject, it isn't clear to me how to configure a bucket to allow the use of multiple MFA devices for authentication. That is, allow any one of several registered MFA devices to authenticate requests for deletions.

The idea here is to allow a small group of employees, each with their own MFA devices, to have access to programmatically delete objects from an S3 bucket that's configured to require MFA. With only a single device configured per-bucket, we're in a "hit by a bus" situation.

Is there a way to do this? Or are we better off pursuing a shared MFA solution (KeepassXC, Dashlane, etc.). An online password management tool that allows shared (controlled) access to an MFA token would work, but if possible I'd prefer to devise a solution that stays within AWS IAM.

Thanks!

1개 답변
0

Hii ..., S3 MFA delete is huge management overhead for the Cloud Administrator. Its actually not recomended to share the MFA of root user with others or having Multiple MFA devices because its a** security concern.** S3 MFA is enabled for a critical data where a root account holder is only allowed to authorize to delete.

답변함 2년 전

전문가

검토됨 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.