Cognito user pool without MFA

Configure the additional authentication required for password sign-in.

Description

When MFA is disabled in a Cognito user pool, password sign-in does not require a second authentication factor. OPTIONAL does not require every user to use MFA either.

Potential impact

A compromised password can present a greater risk of account access without an additional authentication step.

Remediation

To require MFA, configure MfaConfiguration: "ON" and a supported authentication method. Verify enrollment, sign-in, and account recovery.

Examples

The examples require software token MFA. Users must enroll an authenticator app, and the application must handle MFA challenges.

Before

yaml
Resources:
  UserPool:
    Type: AWS::Cognito::UserPool
    Properties:
      UserPoolName: my-user-pool
      MfaConfiguration: "OFF"

After

yaml
Resources:
  UserPool:
    Type: AWS::Cognito::UserPool
    Properties:
      UserPoolName: my-user-pool
      MfaConfiguration: "ON"
      EnabledMfas:
        - SOFTWARE_TOKEN_MFA

References