Phishing-Resistant Multi-Factor Authentication
Multi-factor authentication (MFA) means you need two things to log in: something you know (a password) and something you hold (a security key). A phishing-resistant key like a FIDO2 security key or passkey proves it is really you and cannot be tricked by a fake website. It is like a house key that only turns in your own front door, so a copied photo of the key is useless.
If you skip it, a stolen or guessed password lets an attacker walk right into your cloud and reach defense data.
- 1Enable Identity Center
- 2Require MFA
- 3Allow FIDO2 only
- 4Register keys
- 5Protect root user
- 6Verify login
Give each admin a second backup security key and store it safely, or a lost key can lock you out.
In AWS GovCloud (US), use IAM Identity Center with FIDO2 keys the same way, and prefer FIPS 140-3 validated authenticators to meet CUI and ITAR expectations.