AWS Certified CloudOps Engineer - Associate

MFA, Federation, and Account Security

Hardening the credentials themselves: the root user and the tasks that still require it, password policy limits, the MFA types AWS supports and how to enforce them, access key hygiene, and the federation options that let you stop creating IAM users at all.

Intermediate 24 minutes 6 Learning Objectives
  1. Identify the tasks that require AWS account root user credentials and the controls that protect it
  2. Configure an account password policy within the ranges AWS allows and predict which settings apply immediately
  3. Compare the 3 MFA types AWS supports and choose the phishing-resistant option
  4. Enforce MFA on sensitive actions and explain which STS operations can carry MFA information
  5. Decide when an IAM user with long-term access keys is still the right answer
  6. Choose between IAM Identity Center, SAML or OIDC federation in IAM, and Amazon Cognito for a given set of users