Can we enforce the use of hardware tokens only for some users in AWS IAM identity center users?

0

Hi all

I know if administrator enables MFA, users must sign in to the AWS access portal with two factors - https://docs.aws.amazon.com/singlesignon/latest/userguide/enable-mfa.html. I'd love to enforce the use of hardware tokens only for some users in AWS IAM identity center users. Is it possible?

Thanks.

asked 7 months ago96 views
2 Answers
0
Accepted Answer

Unfortunately, it's not possible with Identity Center if you're using the IdC native directory. If you're using an external SAML-based identity provider, then MFA is handled on the identity provider side. So you'd have to look at what's supported by the identity provider.

AWS
answered 7 months ago
AWS
EXPERT
reviewed 3 months ago
0

IAM Identity Center lacks selective MFA device enforcement, but integration with an external IdP, additional Identity Center instances, or custom flows with Cognito can provide alternatives to achieve similar MFA control over selected user groups.

answered 7 months ago
  • Hi, @Basel Mohamed, can you elaborate on how to do that? Any references? Thanks.

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions