VCEWin

Learn By Self | Served By Experts

Buy Here: AWS Cloud Step By Step Lab Manual Guide

Deal of the month

Windows Server 2016 Hands-on Practical Guide with Virtual Machine Lab Setup

  • CCNA
    • Routing
    • Switching
    • IPv6
    • Security
    • Juniper
  • GNS3 Labs
  • VMware
  • VirtualBox
  • Windows
    • Windows Server 2016
    • Windows 10
    • SCVMM
  • Linux
    • Ubuntu
    • RHEL
  • AWS Cloud
  • Blogging Tutorilas
    • Internet Tips
You are here: Home / AWS Cloud / How To Enable MFA For AWS IAM And Root Users

April 25, 2017 by VCEWin

How To Enable MFA For AWS IAM And Root Users

Security for AWS console is the prime concern for Cloud administrator. Every user including AWS Root Account should be enabled with Multi-Factor Authentication (MFA) for secure AWS console login. The MFA feature adds an additional layer of security while login to AWS console. You can enable MFA for AWS IAM or root user using either a hardware-based MFA device or a virtual MFA application. There are various virtual MFA applications are available to use. The following virtual MFA applications are available for mobile devices:

  • Android: Google Authenticator; Authy 2-Factor Authentication
  • iPhone: Google Authenticator; Authy 2-Factor Authentication
  • Windows Phone: Authenticator+
  • Blackberry: Google Authenticator

Recommended articles: Recover EC2 Linux Instance if the private key is lost.

You can also use the hardware-based MFA device, however, you may need to pay something to purchase it. This article
is focused on virtual MFA application.

Before proceeding to the next, process, make sure you have installed the appropriate virtual MFA application for your mobile device.

Enabling Multi-factor Authentication for AWS User

To enable MFA for AWS IAM user, you need to perform the following steps:

  1. Login to the AWS Management Console with admin privileges.
  2. Search and open the IAM users dashboard.
  3.  In the left pane, click Users and select an IAM user for which you want to enable MFA.
  4. In the IAM user Summary page, select the Security Credentials tab and then click Assign MFA device edit button as shown in the following figure.Enable MFA for AWS IAM users
  5. On the Manage MFA Device window, select the type of MFA device to activate. For this exercise, we will select A virtual MFA device option as shown in the following figure.Hardware MFA for AWS IAM user
  6. Click Next Step to proceed. On the warning message box, read the instruction and click the Next Step button to proceed.
  7. On the next page, you will see a scan code that you need to scan using the Virtual MFA Application such as Google Authenticator.
  8. Once the code is scanned, the virtual MFA device (in our case Android mobile) should be able to detect the AWS user account.
  9. On the Scan Code page of AWS console, you also need to type two consecutive codes displayed on the Google Authenticator application.
  10. Now click Activate MFA Device button to proceed as shown in the following figure.Note: The authentication code changes after every few seconds so be careful while typing correct authentication code.
  11. Once the process is completed “The MFA device was successfully associated.” message will be displayed. Click Finish to complete the wizard.
  12. Now, whenever the IAM user will try to login to AWS console, he will need the dynamic security code along with username and password.

That’s all you need to do to enable MFA for AWS IAM user. The same process can be followed to enable MFA for AWS root account. However, you must be logged in with root account to do so.

Hope, you have loved this article. in the next article, we will discuss what to do if the associated MFA device is lost. You should know this especially in case of AWS root account. Because IAM user cannot manage MFA for AWS root account.

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • Click to share on Google+ (Opens in new window)
❮❮ Previous Post
Next Post ❯ ❯

Windows Server 2016 – Lab Manual Guide

The Best CCNA Self Study Guide

Like Us

AWS Cloud Self Learning Guide

Recent Posts

  • How To Scan EC2 Instances Using Amazon Inspector
  • Creating and Using AWS NAT Gateways – Step By Step
  • How To Create and Use AWS Internet Gateways
  • How To Create and Manage AWS Virtual Private Cloud (VPC)
  • Step By Step Guide To Create AWS Account Without Credit Card

Newsletter

  • Contact Us
  • Terms and Conditions
  • About Us

Copyright © ‘2019’ · VCEWin ·

Pretty Chic Theme By: Pretty Darn Cute Design