Cognito advanced security features are disabled

Severity
Low
Service
Cognito
Check ID
COGNITO_ADVANCED_SECURITY_DISABLED

What this check finds

The user pool has AdvancedSecurityMode=OFF, so Cognito threat protection — compromised-credential detection and adaptive (risk-based) authentication — is not active. Sign-ins from known-leaked credentials or anomalous risk contexts are neither blocked nor logged.

Passing looks like: Cognito advanced security enabled.

How to fix it

Enable advanced security (set to AUDIT to monitor, or ENFORCED to block risky sign-ins). Note this requires the Cognito Plus feature plan. Cognito console → User pools → select pool → Sign-in experience → Threat protection.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to Cognito advanced security features are disabled
FrameworkControls
NIST SP 800-53 Rev5 (Moderate)
  • IA-2 Identification and Authentication (Organizational Users)
  • SI-4 System Monitoring
NIST Cybersecurity Framework 2.0
  • PR.AA-03 Users, services, and hardware are authenticated
  • DE.CM-01 Networks are monitored
ISO/IEC 27001:2022 Annex A
  • A.8.5 Secure authentication
  • A.8.16 Monitoring activities

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More Cognito checks

All Cognito checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only