AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A security team needs to ensure that all IAM users in a specific AWS account are forced to enable multi-factor authentication (MFA) for console access. If a user attempts to access the console without MFA, the access should be denied. Which IAM policy condition should be used to enforce this requirement?

  1. A```json { "Condition": { "NumericGreaterThan": { "aws:MultiFactorAuthAge": "0" } } } ```
  2. B```json { "Condition": { "Null": { "aws:MultiFactorAuthPresent": "false" } } } ```
  3. C```json { "Condition": { "StringEquals": { "aws:MultiFactorAuthAge": "0" } } } ```
  4. D```json { "Condition": { "Bool": { "aws:MultiFactorAuthPresent": "true" } } } ```
Show answer & explanation

Correct answer: A. ```json { "Condition": { "NumericGreaterThan": { "aws:MultiFactorAuthAge": "0" } } } ```

The `aws:MultiFactorAuthAge` condition key checks how long ago (in seconds) the user authenticated with MFA. By setting `NumericGreaterThan: {"aws:MultiFactorAuthAge": "0"}`, the policy ensures that the user has authenticated with MFA within the current session, effectively requiring MFA for the action. This condition is typically used in a 'Deny' statement for actions where MFA is required, or in an 'Allow' statement where MFA is a prerequisite for permission.

Why the other options are wrong

  • B. `Null": {"aws:MultiFactorAuthPresent": "false"}` incorrectly uses the `Null` operator. `Null` checks if a condition key is present at all. `aws:MultiFactorAuthPresent` is a boolean, so `Null` is not the right operator for its value.
  • C. `aws:MultiFactorAuthAge": "0"` would mean the MFA authentication happened exactly 0 seconds ago, which is generally not practical or useful. It doesn't enforce that MFA *was* used in the current session.
  • D. `aws:MultiFactorAuthPresent": "true"` is used in an `Allow` statement to grant access *if* MFA is present. To *deny* access if MFA is *not* present, or to ensure MFA *was* used, `aws:MultiFactorAuthAge` is more precise, especially for console access where a session might exist without recent MFA.

IAM Condition Key: aws:MultiFactorAuthAge

An IAM condition key that specifies the number of seconds since the IAM principal authenticated with multi-factor authentication (MFA).

  • Value is an integer representing seconds.
  • A value of '0' means MFA was not used for the current session.
  • Commonly used with `NumericGreaterThan` to enforce MFA for sensitive actions.
  • Can be used in `Allow` or `Deny` statements to control access based on MFA.

Memory trick: MFA Age greater than zero, makes your access a secure hero.

More Domain 4: Identity and Access Management questions