I’m really pleased to share that today, AWS announced we’ll begin requiring the use of MFA in 2024, beginning with the most privileged accounts in our customer environments - the management account root users of AWS Organizations - and expanding throughout 2024.
MFA and strong authentication are so critical, so foundational to security health. It’s increasingly obvious that as digital identity evolves, everyone, everywhere should be using some form of MFA - and if that’s phishing-resistant authentication like #FIDO all the better. As an identity practitioner and as a consumer impacted by the security choices of the companies I do business with, I hope we will continue to see a growing number of companies emphasizing - and yes, requiring - MFA, because it makes a better internet for all of us.
On a personal note: I’ve been at Amazon for ~11 years now, which means I have a pretty big sample size to compare to when I say this is the happiest, most gratifying working day of my life.
https://aws.amazon.com/blogs/security/security-by-design-aws-to-enhance-mfa-requirements-in-2024/
Secure by Design: AWS to enhance MFA requirements in 2024 | Amazon Web Services
Security is our top priority at Amazon Web Services (AWS). To that end, I’m excited to share that AWS is further strengthening the default security posture of our customers’ environments by requiring the use of multi-factor authentication (MFA), beginning with the most privileged users in their accounts. MFA is one of the simplest and most […]
