← All posts

Technical Post · Amazon Web Services

Creating an MFA-based access restriction policy for IAM users

In this post, we'll see how to create a multi-factor authentication (MFA) condition policy to restrict access to AWS services for…

1 min read288 wordsSections: 2Images: 1Code blocks: 2Sep 19, 2022

Keywords

Share
Comment

In this post, we'll see how to create a multi-factor authentication (MFA) condition policy to restrict access to AWS services for AWS Identity and Access Management (IAM) users. The policy works with both the AWS Management Console and the AWS Command Line Interface (AWS CLI).

Creating an MFA-based access restriction policy for IAM users

  • Create the “BlockMostAccessUnlessSignedInWithMFA” policy with the manifest below:
{
   “Version”: “2012–10–17”,
   “Statement”:
   [
      {
          “Sid”: “BlockMostAccessUnlessSignedInWithMFA”,
          “Effect”: “Deny”,
          “NotAction”:
          [
             “iam:CreateVirtualMFADevice”,
             “iam:DeleteVirtualMFADevice”,
             “iam:ListVirtualMFADevices”,
             “iam:EnableMFADevice”,
             “iam:ResyncMFADevice”,
             “iam:ListAccountAliases”,
             “iam:ListUsers”,
             “iam:ListSSHPublicKeys”,
             “iam:ListAccessKeys”,
             “iam:ListServiceSpecificCredentials”,
             “iam:ListMFADevices”,
             “iam:GetAccountSummary”,
             “sts:GetSessionToken”
          ],
          “Resource”: “*”,
          “Condition”:
          {
             “Bool”:
             {
                 “aws:MultiFactorAuthPresent”: “false”
             }
          }
      }
   ]
}
  • Attach this policy to all IAM groups currently in use. This way, MFA becomes mandatory for every IAM user.

Considerations for using MFA with the AWS CLI

The MultiFactorAuthPresent key applies only to temporary security credentials that verify whether MFA was used. The MultiFactorAuthPresent key does not deny access to requests made with long-term credentials or to MFA requests made with the AWS CLI.

IAM users who use the AWS Management Console generate temporary credentials and are allowed access only if MFA is used.

The Bool condition operator lets you restrict access with a key value set to true or false . You can add the BoolIfExists condition operator to check whether the MultiFactorAuthPresent key is present in the request. If the MultiFactorAuthPresent key is not present, IfExists evaluates the condition element as true, similar to the following:

“Effect” : “Deny”,
“Condition” : { “BoolIfExists” : { “aws:MultiFactorAuthPresent” : “false” } }

IAM users who use the AWS CLI with long-term credentials are denied access and must use MFA to authenticate.

See you in the next post! =)

Comments

Every comment is moderated before it appears here. Nothing is published automatically.

Loading…