Review S3 bucket MFA Delete use

Consider whether permanent deletion of important object versions needs additional authentication.

Description

MFA Delete on a versioned bucket requires additional authentication for permanent object-version deletion and changes to the versioning state. Without it, a principal with the relevant permissions can perform those operations without an MFA check. It does not require MFA for every ordinary object-delete request.

Potential impact

  • Stolen permissions or operator mistakes can permanently delete versions needed for recovery.
  • Versioning alone does not prevent deletion of every version.

Remediation

Evaluate MFA Delete against data-retention requirements. Only the bucket owner’s root user can enable it through the AWS CLI or API using an MFA device. Verify the actual enabled state and strictly control root access. MFA Delete cannot be used with S3 Lifecycle configurations.

Examples

These excerpts use the legacy inline versioning syntax from AWS provider 3.75.2. In that version, mfa_delete reflects the actual AWS state; changing it in Terraform does not enable MFA Delete.

Before

hcl
resource "aws_s3_bucket" "example" {
  bucket = "my-tf-test-bucket"
  acl    = "private"

  versioning {
    enabled = true
  }
}

After

hcl
resource "aws_s3_bucket" "example" {
  bucket = "my-tf-test-bucket"
  acl    = "private"

  versioning {
    enabled    = true
    mfa_delete = true
  }
}

The second example declares MFA Delete that has been enabled separately in AWS. Confirm the actual versioning and MFA Delete states before applying it.

References