AWS IAM Identity Center -- Identity Source MFA

0

After enabling AWS IAM Identity Center in our primary account for our organization, and intending to change the identity source to an external one for use with Google Workspace, I was presented with a bullet list of consequences to changing the identity source. The main one that struck me was bullet #2:

IAM Identity Center will delete your current multi-factor authentication (MFA) configuration.

It is unclear what this is referring to exactly, and I was unable to find any clarification in the documentation for AWS IAM Identity Center.

Is this only supposed to affect a given identity source if we had one set up already? (In this case, we didn't) Or would it affect existing IAM users in the primary account? Or would it affect the root user of the primary account?

Thank you for any clarification that can be provided.

1回答
1
承認された回答

We believe that even if MFA is disabled in the AWS IAM identity center, the root user's MFA will not be disabled.
https://docs.aws.amazon.com/accounts/latest/reference/root-user-vs-iam.html

As stated in this document, I thought it was separated from the IAM identity center as it states that the root user's MFA only affects the root user.
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html

You can enable MFA for the AWS account root user and IAM users. When you enable MFA for the root user, it affects only the root user credentials.

profile picture
エキスパート
回答済み 10ヶ月前
profile picture
エキスパート
レビュー済み 1ヶ月前
  • Thank you for your answer. This was confirmed by creating a completely separate AWS account and testing it there. After changing the Identity Source, the root user's MFA and the MFA of existing IAM users were all unaffected.

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ