내용으로 건너뛰기

Can we enforce the use of hardware tokens only for some users in AWS IAM identity center users?

0

Hi all

I know if administrator enables MFA, users must sign in to the AWS access portal with two factors - https://docs.aws.amazon.com/singlesignon/latest/userguide/enable-mfa.html. I'd love to enforce the use of hardware tokens only for some users in AWS IAM identity center users. Is it possible?

Thanks.

질문됨 2년 전191회 조회

2개 답변
0
수락된 답변

Unfortunately, it's not possible with Identity Center if you're using the IdC native directory. If you're using an external SAML-based identity provider, then MFA is handled on the identity provider side. So you'd have to look at what's supported by the identity provider.

AWS

답변함 2년 전

전문가

검토됨 일 년 전

0

IAM Identity Center lacks selective MFA device enforcement, but integration with an external IdP, additional Identity Center instances, or custom flows with Cognito can provide alternatives to achieve similar MFA control over selected user groups.

답변함 2년 전

  • Hi, @Basel Mohamed, can you elaborate on how to do that? Any references? Thanks.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.