IAM-02.2: MFA is required for access to the cloud console/portal. This is typically enforced at the SSO level. This may not be possible to automatically assess when an external SSO provider is used.
  • Control automation: Either
  • AWS control specification: 1. MFA is enforced within AWS Identity Center or MFA status is passed as a federation attribute for the IdP and used within an MFA-required IAM policy
  1. MFA is required for all IAM users with console access
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Either
  • AWS control specification: 1. MFA is enforced within AWS Identity Center or MFA status is passed as a federation attribute for the IdP and used within an MFA-required IAM policy
  1. MFA is required for all IAM users with console access
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none