1 Answer
- Newest
- Most votes
- Most comments
0
In addition to hardware TOTP token, passkey or security key will meet the requirement for IAM.6 control in Security Hub.
For example, a passkey using Chrome profile or a FIDO2 security key configured for the root user will generate a PASSED check for IAM.6 control.
Please refer the below links for more information on FIDO2 security key support in IAM. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_fido_supported_configurations.html#id_credentials_mfa_fido_supported_devices https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_mfa-fido.html
For supported Yubico devices, please use this link and search for FIDO2 specification keys https://fidoalliance.org/certification/fido-certified-products/
Relevant content
- asked a year ago
- asked 3 years ago
- AWS OFFICIALUpdated 6 months ago
- AWS OFFICIALUpdated 4 years ago
