1 Answer
- Newest
- Most votes
- Most comments
1
Hello,
There are two controls associated with MFA:
- Enabling MFA
- Enforcing MFA
Also, the working is different for Console and CLI access.
When MFA is enabled for a particular IAM user it is enforced in the Console only and not in CLI. If you wish you can enforce MFA in CLI for your IAM user by attaching the policy given in the document [1] on the user.
Thus to conclude, if you want to enforce MFA for console sign-in but not for CLI access, then just enable MFA for the IAM user and there is no need to apply any policy on the user. The MFA will be enforced automatically.
Let us know know in case you require further assistance.
References:
[1] Create a Policy to Enforce MFA Sign-In:
answered 6 years ago
Relevant content
- asked 2 years ago
- asked 2 years ago
- asked 6 months ago
- AWS OFFICIALUpdated 4 months ago
- AWS OFFICIALUpdated 4 months ago
- AWS OFFICIALUpdated 6 months ago
- AWS OFFICIALUpdated 5 months ago