A security team needs to ensure that all IAM users in a specific AWS account are forced to enable multi-factor authentication (MFA) for console access. If a user attempts to access the console without MFA, the access should be denied. Which IAM policy condition should be used to enforce this requirement?
- A```json { "Condition": { "NumericGreaterThan": { "aws:MultiFactorAuthAge": "0" } } } ```
- B```json { "Condition": { "Null": { "aws:MultiFactorAuthPresent": "false" } } } ```
- C```json { "Condition": { "StringEquals": { "aws:MultiFactorAuthAge": "0" } } } ```
- D```json { "Condition": { "Bool": { "aws:MultiFactorAuthPresent": "true" } } } ```
Show answer & explanationAnswer & explanation
Correct answer: A. ```json { "Condition": { "NumericGreaterThan": { "aws:MultiFactorAuthAge": "0" } } } ```
The `aws:MultiFactorAuthAge` condition key checks how long ago (in seconds) the user authenticated with MFA. By setting `NumericGreaterThan: {"aws:MultiFactorAuthAge": "0"}`, the policy ensures that the user has authenticated with MFA within the current session, effectively requiring MFA for the action. This condition is typically used in a 'Deny' statement for actions where MFA is required, or in an 'Allow' statement where MFA is a prerequisite for permission.
Why the other options are wrong
- B. `Null": {"aws:MultiFactorAuthPresent": "false"}` incorrectly uses the `Null` operator. `Null` checks if a condition key is present at all. `aws:MultiFactorAuthPresent` is a boolean, so `Null` is not the right operator for its value.
- C. `aws:MultiFactorAuthAge": "0"` would mean the MFA authentication happened exactly 0 seconds ago, which is generally not practical or useful. It doesn't enforce that MFA *was* used in the current session.
- D. `aws:MultiFactorAuthPresent": "true"` is used in an `Allow` statement to grant access *if* MFA is present. To *deny* access if MFA is *not* present, or to ensure MFA *was* used, `aws:MultiFactorAuthAge` is more precise, especially for console access where a session might exist without recent MFA.
IAM Condition Key: aws:MultiFactorAuthAge
An IAM condition key that specifies the number of seconds since the IAM principal authenticated with multi-factor authentication (MFA).
- Value is an integer representing seconds.
- A value of '0' means MFA was not used for the current session.
- Commonly used with `NumericGreaterThan` to enforce MFA for sensitive actions.
- Can be used in `Allow` or `Deny` statements to control access based on MFA.
Memory trick: MFA Age greater than zero, makes your access a secure hero.