Review Cognito User Pool MFA coverage

Apply MFA to password-based sign-ins where required and verify the coverage of optional settings.

Description

Without MFA on password-based Cognito User Pool sign-ins, leaked or reused passwords can more readily lead to account takeover. The default mfa_configuration value, OFF, does not require MFA.

ON requires MFA, while OPTIONAL applies it only to users who have configured it. For sign-ins through an external IdP, check that provider's MFA policy separately.

Potential impact

  • A leaked password may be used to abuse an account without an additional authentication step.
  • Users who have not enrolled in optional MFA do not receive the same protection.

Remediation

  • Check the service's authentication methods and recovery procedures, and use ON when MFA must be required. If choosing OPTIONAL, manage user enrollment and actual coverage.
  • Configure supported MFA methods and test enrollment, sign-in and recovery after device loss. For SMS, also provide the required delivery permissions and role.

Examples

These excerpts show MFA settings and omit the required user pool name and referenced role. The revised example makes software-token MFA optional; it does not require MFA for every user.

Before

hcl
resource "aws_cognito_user_pool" "example" {
  mfa_configuration          = "OFF"
  sms_authentication_message = "Your code is {####}"

  sms_configuration {
    external_id    = "example"
    sns_caller_arn = aws_iam_role.example.arn
  }

  software_token_mfa_configuration {
    enabled = true
  }
}

After

hcl
resource "aws_cognito_user_pool" "example" {
  mfa_configuration          = "OPTIONAL"
  sms_authentication_message = "Your code is {####}"

  software_token_mfa_configuration {
    enabled = true
  }
}

Explanation:

  • Before: Configuring MFA methods does not require MFA while the setting is OFF.
  • After: Users who enroll in MFA can use software tokens. Review mandatory enforcement if users who have not enrolled also need protection.

References