Description
When MFA is disabled in a Cognito user pool, password sign-in does not require a second authentication factor. OPTIONAL does not require every user to use MFA either.
Potential impact
A compromised password can present a greater risk of account access without an additional authentication step.
Remediation
To require MFA, configure MfaConfiguration: "ON" and a supported authentication method. Verify enrollment, sign-in, and account recovery.
Examples
The examples require software token MFA. Users must enroll an authenticator app, and the application must handle MFA challenges.
Before
yaml
Resources:
UserPool:
Type: AWS::Cognito::UserPool
Properties:
UserPoolName: my-user-pool
MfaConfiguration: "OFF"
After
yaml
Resources:
UserPool:
Type: AWS::Cognito::UserPool
Properties:
UserPoolName: my-user-pool
MfaConfiguration: "ON"
EnabledMfas:
- SOFTWARE_TOKEN_MFA