跳至內容

Can we enforce the use of hardware tokens only for some users in AWS IAM identity center users?

0

Hi all

I know if administrator enables MFA, users must sign in to the AWS access portal with two factors - https://docs.aws.amazon.com/singlesignon/latest/userguide/enable-mfa.html. I'd love to enforce the use of hardware tokens only for some users in AWS IAM identity center users. Is it possible?

Thanks.

已提問 2 年前檢視次數 191 次

2 個答案
0
已接受的答案

Unfortunately, it's not possible with Identity Center if you're using the IdC native directory. If you're using an external SAML-based identity provider, then MFA is handled on the identity provider side. So you'd have to look at what's supported by the identity provider.

AWS

已回答 2 年前

專家

已審閱 1 年前

0

IAM Identity Center lacks selective MFA device enforcement, but integration with an external IdP, additional Identity Center instances, or custom flows with Cognito can provide alternatives to achieve similar MFA control over selected user groups.

已回答 2 年前

  • Hi, @Basel Mohamed, can you elaborate on how to do that? Any references? Thanks.

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。