AWS SAA – Lecture 16: IAM MFA Overview

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
protect (an account)add security measures to prevent unauthorized access
compromise (an account)gain unauthorized access to it
prevent password reuseblock users from reusing old passwords
require (a character type)make something mandatory in a password
generate (a token)produce a one-time code from an MFA device

Technical Vocabulary

TermDefinition
Password policyA set of rules enforced by AWS for IAM user passwords (length, complexity, expiry, reuse)
MFA (Multi-Factor Authentication)A security method combining something you know (password) + something you own (device)
Brute force attackTrying many combinations of passwords to guess the correct one
Virtual MFA deviceSoftware app on a phone that generates time-based one-time codes (e.g., Google Authenticator, Authy)
U2F Security KeyA physical USB/NFC key (e.g., YubiKey by Yubico) used as a second factor
Hardware key fobA dedicated physical device that generates OTP codes (e.g., Gemalto device)
GovCloudAWS regions dedicated to US government workloads; uses a special SurePassID key fob
One-Time Password (OTP)A code valid for only one login attempt or a short time window
Root accountThe master account in AWS — must always be protected with MFA

Key Concepts

Defense Mechanism 1 — Password Policy

AWS lets you configure:

  • Minimum password length
  • Required character types: uppercase, lowercase, numbers, non-alphanumeric
  • Allow/disallow IAM users to change their own passwords
  • Password expiry (e.g., every 90 days)
  • Prevent reuse of previous passwords

Purpose: protection against brute force attacks.

Defense Mechanism 2 — MFA

  • What: password (what you know) + MFA device (what you own)
  • Why: even if password is stolen, attacker cannot log in without the physical device
  • Recommendation: enable MFA on the root account at minimum; ideally all IAM users

MFA Device Options

DeviceTypeNotes
Google AuthenticatorVirtual MFAOne phone at a time
AuthyVirtual MFAMultiple tokens/devices supported
YubiKey (U2F)Physical hardware keySupports multiple root/IAM users on one key; by Yubico
Gemalto key fobHardware OTP deviceThird-party hardware device
SurePassID key fobHardware OTP deviceFor AWS GovCloud (US) only

Exam Tips

  • Know the two defense mechanisms: password policy + MFA
  • Know all 4 MFA device types: Virtual (Authenticator/Authy), U2F hardware key, hardware key fob, GovCloud key fob
  • Root account + IAM users should use MFA
  • MFA = password AND a device — both are required