79376801

Date: 2025-01-22 07:12:25
Score: 2
Natty:
Report link

The issue is that MFA enforcement can differ from attaching policies directly to users and using assume role. I would create one policy that assumes the role and ensures MFA is present and a trust policy that ensures the role enforces MFA during assumption. MFA needs to be enforced on the trust policy and removed from the regular policy.

As discussed and confirmed by @Vincent Verbist.

Reasons:
  • No code block (0.5):
  • User mentioned (1): @Vincent
  • Low reputation (0.5):
Posted by: root69