Description
Without MFA on password-based Cognito User Pool sign-ins, leaked or reused passwords can more readily lead to account takeover. The default mfa_configuration value, OFF, does not require MFA.
ON requires MFA, while OPTIONAL applies it only to users who have configured it. For sign-ins through an external IdP, check that provider's MFA policy separately.
Potential impact
- A leaked password may be used to abuse an account without an additional authentication step.
- Users who have not enrolled in optional MFA do not receive the same protection.
Remediation
- Check the service's authentication methods and recovery procedures, and use
ONwhen MFA must be required. If choosingOPTIONAL, manage user enrollment and actual coverage. - Configure supported MFA methods and test enrollment, sign-in and recovery after device loss. For SMS, also provide the required delivery permissions and role.
Examples
These excerpts show MFA settings and omit the required user pool name and referenced role. The revised example makes software-token MFA optional; it does not require MFA for every user.
Before
hcl
resource "aws_cognito_user_pool" "example" {
mfa_configuration = "OFF"
sms_authentication_message = "Your code is {####}"
sms_configuration {
external_id = "example"
sns_caller_arn = aws_iam_role.example.arn
}
software_token_mfa_configuration {
enabled = true
}
}
After
hcl
resource "aws_cognito_user_pool" "example" {
mfa_configuration = "OPTIONAL"
sms_authentication_message = "Your code is {####}"
software_token_mfa_configuration {
enabled = true
}
}
Explanation:
- Before: Configuring MFA methods does not require MFA while the setting is
OFF. - After: Users who enroll in MFA can use software tokens. Review mandatory enforcement if users who have not enrolled also need protection.