Description
MFA Delete on a versioned bucket requires additional authentication for permanent object-version deletion and changes to the versioning state. Without it, a principal with the relevant permissions can perform those operations without an MFA check. It does not require MFA for every ordinary object-delete request.
Potential impact
- Stolen permissions or operator mistakes can permanently delete versions needed for recovery.
- Versioning alone does not prevent deletion of every version.
Remediation
Evaluate MFA Delete against data-retention requirements. Only the bucket owner’s root user can enable it through the AWS CLI or API using an MFA device. Verify the actual enabled state and strictly control root access. MFA Delete cannot be used with S3 Lifecycle configurations.
Examples
These excerpts use the legacy inline versioning syntax from AWS provider 3.75.2. In that version, mfa_delete reflects the actual AWS state; changing it in Terraform does not enable MFA Delete.
Before
resource "aws_s3_bucket" "example" {
bucket = "my-tf-test-bucket"
acl = "private"
versioning {
enabled = true
}
}
After
resource "aws_s3_bucket" "example" {
bucket = "my-tf-test-bucket"
acl = "private"
versioning {
enabled = true
mfa_delete = true
}
}
The second example declares MFA Delete that has been enabled separately in AWS. Confirm the actual versioning and MFA Delete states before applying it.