MFA for API calls

Information

Multi-factor authentication (MFA)-protected API access requires IAM users to enter a valid MFA code before they can use certain functions, which are APIs. Policies you create in IAM will determine which APIs require MFA. Because the AWS Management Console calls AWS service APIs, you can enforce MFA on APIs whether access is through the console or via APIs.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-3, 800-53|AC-11, 800-53|AU-2, 800-53|AU-11, 800-53|IA-1, 800-53|IA-2, 800-53|IA-5, 800-53|IA-6, 800-53|IA-8, 800-53|SC-10

Plugin: amazon_aws

Control ID: 63e024d6c968297a49e99a38ef0511750f51350187a7562bfa0011cadefe1b0b