Cognito user pool does not enforce MFA

Severity
Medium
Service
Cognito
Check ID
COGNITO_MFA_DISABLED

What this check finds

The user pool's MfaConfiguration is OFF, so accounts are protected by a password alone. Credential stuffing or phishing of a single password is enough to take over an account. MFA (OPTIONAL or ON) materially reduces account-takeover risk.

Passing looks like: Cognito user pool enforces MFA.

How to fix it

Enable MFA on the user pool (set to ON to require it, or OPTIONAL to allow per-user enrollment) and configure SMS and/or TOTP factors. Cognito console → User pools → select pool → Sign-in experience → Multi-factor authentication.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to Cognito user pool does not enforce MFA
FrameworkControls
PCI-DSS v4.0.1
  • 8.3 Strong authentication for users and administrators is established and managed
NIST SP 800-53 Rev5 (Moderate)
  • IA-2 Identification and Authentication (Organizational Users)
NIST Cybersecurity Framework 2.0
  • PR.AA-03 Users, services, and hardware are authenticated
ISO/IEC 27001:2022 Annex A
  • A.8.5 Secure authentication

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More Cognito checks

All Cognito checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only