AWS IAM Identity Center -- Identity Source MFA

0

After enabling AWS IAM Identity Center in our primary account for our organization, and intending to change the identity source to an external one for use with Google Workspace, I was presented with a bullet list of consequences to changing the identity source. The main one that struck me was bullet #2:

IAM Identity Center will delete your current multi-factor authentication (MFA) configuration.

It is unclear what this is referring to exactly, and I was unable to find any clarification in the documentation for AWS IAM Identity Center.

Is this only supposed to affect a given identity source if we had one set up already? (In this case, we didn't) Or would it affect existing IAM users in the primary account? Or would it affect the root user of the primary account?

Thank you for any clarification that can be provided.

已提問 10 個月前檢視次數 331 次
1 個回答
1
已接受的答案

We believe that even if MFA is disabled in the AWS IAM identity center, the root user's MFA will not be disabled.
https://docs.aws.amazon.com/accounts/latest/reference/root-user-vs-iam.html

As stated in this document, I thought it was separated from the IAM identity center as it states that the root user's MFA only affects the root user.
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html

You can enable MFA for the AWS account root user and IAM users. When you enable MFA for the root user, it affects only the root user credentials.

profile picture
專家
已回答 10 個月前
profile picture
專家
已審閱 1 個月前
  • Thank you for your answer. This was confirmed by creating a completely separate AWS account and testing it there. After changing the Identity Source, the root user's MFA and the MFA of existing IAM users were all unaffected.

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南