Description
Allowing sensitive role assumption without MFA can let exposed IAM user credentials reach stronger permissions. Check whether effective authorization, including the user policy and target role’s trust policy, requires MFA.
aws:MultiFactorAuthPresent is not available with every credential type. Long-term access keys do not themselves carry MFA state; use supported MFA temporary credentials or role-assumption flows. Enforce external IdP MFA through that identity system separately.
Potential impact
- Operations requiring MFA may be allowed with exposed credentials alone.
- Another policy’s Allow can make a condition on one statement insufficient to restrict access.
Remediation
- Where human role assumption requires MFA, constrain both permissions and role trust. An
AllowusingBoolIfExistsalso passes when the key is absent, so it does not reliably require MFA. - Test requests with and without MFA and review other Allow policies. Use suitable workload roles for automation.
Examples
Provide the existing IAM user and actual target role ARN. Identity-based user policies do not contain Principal; the target role’s trust policy is separately required.
Before
resource "aws_iam_user_policy" "example" {
name = "test"
user = aws_iam_user.example.name
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Resource": "${var.target_role_arn}",
"Action": "sts:AssumeRole"
}
]
}
EOF
}
After
resource "aws_iam_user_policy" "example" {
name = "test"
user = aws_iam_user.example.name
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Resource": "${var.target_role_arn}",
"Action": "sts:AssumeRole",
"Condition": {
"Bool": {
"aws:MultiFactorAuthPresent" : "true"
}
}
}
]
}
EOF
}
Explanation:
- Before: This statement has no MFA condition on role assumption. Other controls still need review.
- After: This Allow applies only when the MFA value is true. Check separately whether other policies permit access without MFA.