AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A global company uses AWS IAM Identity Center (formerly AWS Single Sign-On) to manage access to multiple AWS accounts for its employees. The company has a requirement that all administrative access to production AWS accounts must enforce multi-factor authentication (MFA). Normal user access to development accounts does not require MFA. How can the security administrator enforce this MFA requirement efficiently using IAM Identity Center?

  1. AConfigure the MFA requirement within the IAM policies attached to the IAM roles in each production account.
  2. BImplement a custom attribute-based access control (ABAC) policy in Identity Center that checks for MFA for production access.
  3. CEnable 'MFA always required' for the Identity Center application accessed by production administrative users.
  4. DCreate a separate permission set for production administrative access and configure an MFA requirement on that specific permission set.
Show answer & explanation

Correct answer: D. Create a separate permission set for production administrative access and configure an MFA requirement on that specific permission set.

IAM Identity Center permission sets are the correct way to define access to AWS accounts. By creating a specific permission set for production administrative access and configuring an MFA requirement directly on that permission set, the administrator can enforce MFA only for those specific access paths, without affecting other users or accounts.

Why the other options are wrong

  • A. While IAM policies can enforce MFA, configuring it within IAM Identity Center permission sets is more efficient and centralized for managing access across multiple accounts.
  • B. While ABAC is powerful, configuring an MFA requirement directly on a permission set is a more straightforward and explicit way to meet this specific requirement within IAM Identity Center.
  • C. Enabling 'MFA always required' for the entire Identity Center application would enforce MFA for all users and all accounts, including development, which is not the specific requirement.

IAM Identity Center Permission Sets

Permission sets in IAM Identity Center define the access permissions and conditions (like MFA) that users or groups get when they assume a role in an AWS account.

  • Centralized access management for multiple accounts.
  • Can enforce MFA for specific access paths.
  • Mapped to roles in target AWS accounts.

Memory trick: Permission Sets precisely control MFA for Identity Center.

More Domain 4: Identity and Access Management questions