{"id":248350,"date":"2026-09-24T00:01:27","date_gmt":"2026-09-24T00:01:27","guid":{"rendered":"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/"},"modified":"2026-09-24T00:01:28","modified_gmt":"2026-09-24T00:01:28","slug":"aws-iam-multi-factor-authentication","status":"publish","type":"post","link":"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/","title":{"rendered":"Stop Phishing: Make FIDO MFA Standard in AWS IAM for Security Teams"},"content":{"rendered":"<div class=\"336cb5b64765e27a1a6c1bb71b941f1a\" data-index=\"1\" style=\"float: none; margin:10px 0 10px 0; text-align:center;\">\n<script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-4830628043307652\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<!-- above content -->\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block\"\r\n     data-ad-client=\"ca-pub-4830628043307652\"\r\n     data-ad-slot=\"5864845439\"\r\n     data-ad-format=\"auto\"\r\n     data-full-width-responsive=\"true\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script>\n<\/div>\n<\/p>\n<p>AWS IAM supports three MFA types: passkeys and security keys (FIDO), virtual authenticator apps (TOTP), and hardware TOTP tokens. AWS recommends phishing-resistant FIDO-based authenticators over TOTP whenever possible. Root user MFA can only be configured through the AWS Management Console, and IAM lets you register up to eight MFA devices per principal for redundancy.<\/p>\n<hr>\n<blockquote>\n<p><strong>TL;DR:<\/strong><\/p>\n<ul>\n<li>FIDO-based passkeys and security keys are the most phishing-resistant MFA options, while virtual authenticator apps are easier to deploy but prone to clock drift issues.<\/li>\n<li>AWS recommends enabling MFA immediately on the root account via the console and registering multiple backup devices to prevent lockouts.<\/li>\n<li>MFA enforcement for IAM users should be implemented through policies, with up to eight devices per user, and organizations should centralize identity management to reduce operational overhead.<\/li>\n<li>Clock drift often causes TOTP codes to fail, so syncing devices regularly and registering backup MFA devices are essential for reliable access.<\/li>\n<li>Passkeys and security keys should become the default MFA method rather than an upgrade, with virtual apps as a fallback when hardware isn\u2019t practical.<\/li>\n<\/ul>\n<\/blockquote>\n<hr>\n<div data-blg-cta=\"after_tldr\" data-blg-cta-layout=\"banner\" style=\"margin:28px 0;font-family:-apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif\">\n<div style=\"border-radius:26px;padding:min(22px,3.2vw)\">\n<div style=\"background:#ffffff;border-radius:18px;overflow:hidden\">\n<div style=\"padding:34px 30px;text-align:center\">\n<div style=\"margin:0 0 18px\"><span style=\"max-width:100%;border-radius:999px;padding:6px 13px;font-size:12px;font-weight:800;letter-spacing:0.1em;text-transform:uppercase;line-height:1.3;background:#F47F24;color:#ffffff\">Logmeonce<\/span><\/div>\n<div style=\"font-size:26px;font-weight:800;line-height:1.2;letter-spacing:-0.01em;color:#1f2937;margin:0\">Strengthen Every Digital Login<\/div>\n<div style=\"width:56px;height:6px;border-radius:3px;background:#F47F24;margin:12px 0 14px;margin-left:auto;margin-right:auto\"><\/div>\n<div style=\"font-size:15px;line-height:1.55;color:#64748b;margin:0 0 24px;max-width:44em;margin-left:auto;margin-right:auto\">Explore LogMeOnce resources for passwordless MFA, identity management, cloud encryption, and dark web monitoring.<\/div>\n<p><a href=\"https:\/\/logmeonce.com\/resources\" style=\"align-items:center;gap:9px;border-radius:10px;font-weight:700;font-size:15px;text-decoration:none;padding:13px 22px 13px 26px;background:#F47F24;color:#ffffff\">Explore security resources<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_77 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#What_MFA_Means_Inside_AWS_IAMs_Identity_Model\" >What MFA Means Inside AWS IAM\u2019s Identity Model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#MFA_Types_Supported_by_AWS_IAM_Passkeys_Virtual_Apps_and_Hardware_Tokens\" >MFA Types Supported by AWS IAM: Passkeys, Virtual Apps, and Hardware Tokens<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#How_to_Enable_MFA_for_IAM_Users_and_the_Root_User\" >How to Enable MFA for IAM Users and the Root User<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#MFA_Best_Practices_for_AWS_Environments\" >MFA Best Practices for AWS Environments<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#Troubleshooting_MFA_Clock_Drift_Lost_Devices_and_Resyncing\" >Troubleshooting MFA: Clock Drift, Lost Devices, and Resyncing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#How_LogMeOnces_Passwordless_MFA_Complements_AWS_IAM\" >How LogMeOnce\u2019s Passwordless MFA Complements AWS IAM<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#Why_Phishing-Resistant_MFA_Should_Be_the_Default_Not_the_Upgrade\" >Why Phishing-Resistant MFA Should Be the Default, Not the Upgrade<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#Sources\" >Sources<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#FAQ\" >FAQ<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#How_Is_MFA_Used_in_IAM\" >How Is MFA Used in IAM?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#How_Do_I_Set_Up_AWS_Multi-Factor_Authentication_in_IAM\" >How Do I Set Up AWS Multi-Factor Authentication in IAM?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#What_Is_the_Difference_Between_IAM_and_SSO\" >What Is the Difference Between IAM and SSO?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/logmeonce.com\/resources\/aws-iam-multi-factor-authentication\/#Where_Do_I_Find_My_AWS_MFA_Code\" >Where Do I Find My AWS MFA Code?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2 id=\"what-mfa-means-inside-aws-iams-identity-model\"><span class=\"ez-toc-section\" id=\"What_MFA_Means_Inside_AWS_IAMs_Identity_Model\"><\/span>What MFA Means Inside AWS IAM\u2019s Identity Model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>MFA adds a second proof of identity on top of a password or access key, and it fits directly into IAM\u2019s least-privilege philosophy: even a leaked credential is useless without the second factor. AWS\u2019s identity model has three layers where MFA matters differently. The root user, tied to the account\u2019s billing and full control, needs MFA the moment the account exists. IAM users, the individual accounts your team logs in with, need MFA enforced through policy. Federated identities, managed through IAM Identity Center or an external identity provider, typically inherit MFA from that provider rather than configuring it inside IAM directly.<\/p>\n<p>The payoff is concrete. MFA blocks the overwhelming majority of account takeovers that start with a stolen or guessed password, and it adds a layer that survives credential-stuffing attacks entirely. It also pairs naturally with temporary credentials and session tokens, since a compromised short-lived token is far less useful to an attacker who still can\u2019t pass the second factor.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/media.babylovegrowth.ai\/blog-images\/organization-6456\/1790165227571_What-MFA-Means-Inside-AWS-IAM-s-Identity-Model-overview-diagram.jpeg\" alt=\"What MFA Means Inside AWS IAM&#039;s Identity Model \u2014 overview diagram\" title=\"\"><\/p>\n<h2 id=\"mfa-types-supported-by-aws-iam-passkeys-virtual-apps-and-hardware-tokens\"><span class=\"ez-toc-section\" id=\"MFA_Types_Supported_by_AWS_IAM_Passkeys_Virtual_Apps_and_Hardware_Tokens\"><\/span>MFA Types Supported by AWS IAM: Passkeys, Virtual Apps, and Hardware Tokens<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Each method AWS supports for MFA in IAM trades off security strength against deployment friction. AWS does not charge extra for any of them, so cost isn\u2019t the deciding factor. Notably, AWS has retired SMS-based MFA in IAM, and the <a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_credentials_mfa.html\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">current guidance<\/a> pushes everyone still using it toward passkeys, virtual apps, or hardware tokens.<\/p>\n<p><strong>Passkeys and security keys (FIDO).<\/strong> These rely on public key cryptography rather than a shared secret, which is what makes them phishing resistant: there\u2019s no code to intercept or trick someone into typing on a fake login page. Some passkeys sync across a user\u2019s devices through a platform vendor, while security keys stay bound to a single physical device. The <a href=\"https:\/\/fidoalliance.org\/fido2\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">FIDO Alliance<\/a> maintains the certification standards that back this approach.<\/p>\n<p><strong>Virtual authenticator apps (TOTP).<\/strong> These generate a six-digit code every 30 seconds using the RFC 6238 TOTP algorithm. They\u2019re free, work on any smartphone, and need no extra hardware. Their weak point is clock drift: if the app\u2019s clock and AWS\u2019s server clock fall out of sync, codes stop validating.<\/p>\n<p><strong>Hardware TOTP tokens.<\/strong> Physical devices that generate the same style of time-based code, useful when phones aren\u2019t allowed near sensitive systems. They carry vendor and seed-provisioning constraints that make large-scale rollout slower than software options.<\/p>\n<ul>\n<li>Passkeys\/security keys: highest phishing resistance, moderate deployability, recovery requires a backup device.<\/li>\n<li>Virtual TOTP apps: strong security, easiest to deploy, prone to clock-drift support tickets.<\/li>\n<li>Hardware TOTP tokens: strong security, slower procurement, no battery or app dependency but easy to misplace.<\/li>\n<\/ul>\n<h2 id=\"how-to-enable-mfa-for-iam-users-and-the-root-user\"><span class=\"ez-toc-section\" id=\"How_to_Enable_MFA_for_IAM_Users_and_the_Root_User\"><\/span>How to Enable MFA for IAM Users and the Root User<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Setting up virtual MFA through the console follows the same basic flow for both IAM users and the root account, with one hard rule: <strong>root user MFA can only be configured through the console<\/strong>, never through the CLI or API, according to AWS\u2019s own guidance. AWS recommends turning it on for the root user the moment the account is created.<\/p>\n<ol>\n<li>Sign in to the account, go to IAM (or Security Credentials for root), and choose \u201cAssign MFA device.\u201d<\/li>\n<li>Select the device type: passkey\/security key, virtual authenticator app, or hardware TOTP token.<\/li>\n<li>For a virtual app, scan the QR code with an authenticator app, then enter two consecutive codes to confirm the device syncs correctly.<\/li>\n<li>For a security key, follow the browser prompt to register the physical device or platform passkey.<\/li>\n<li>Save the device, and repeat the process to register a second backup device where the account allows it.<\/li>\n<\/ol>\n<p>For IAM users, the same actions are scriptable. AWS documents the CLI commands: <code>create-virtual-mfa-device<\/code> to generate the seed, <code>enable-mfa-device<\/code> to attach two codes and activate it, and <code>resync-mfa-device<\/code> to fix a device that\u2019s drifted out of sync. Running this requires <code>iam:CreateVirtualMFADevice<\/code> and <code>iam:EnableMFADevice<\/code> permissions at minimum.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>Grant your team a self-service IAM policy that allows <code>iam:*MFADevice*<\/code> actions scoped to their own user ARN. That single policy change eliminates most MFA-related help desk tickets, since people can register and resync their own devices without waiting on an admin.<\/em><\/p>\n<h2 id=\"mfa-best-practices-for-aws-environments\"><span class=\"ez-toc-section\" id=\"MFA_Best_Practices_for_AWS_Environments\"><\/span>MFA Best Practices for AWS Environments<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>AWS\u2019s own guidance is consistent on ordering: reach for FIDO-based passkeys and security keys first, and treat virtual TOTP apps as an acceptable bridge rather than the end state. A few practices separate teams that handle this well from teams that generate support tickets every quarter.<\/p>\n<ul>\n<li>Register at least two MFA devices per principal, since IAM allows up to <a href=\"https:\/\/aws.amazon.com\/iam\/features\/mfa\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">eight per user<\/a>, and store the backup somewhere separate from the primary device.<\/li>\n<li>Migrate away from SMS entirely, since AWS has ended that method and now points users toward passkeys, virtual apps, or hardware tokens.<\/li>\n<li>Centralize identity through IAM Identity Center or a federated identity provider once you\u2019re managing more than a handful of users, since AWS notes this cuts the operational load of tracking individual MFA registrations.<\/li>\n<li>Enforce MFA through IAM policy conditions rather than relying on people to opt in voluntarily.<\/li>\n<li>Favor roles and temporary credentials for human access over long-lived IAM user access keys, since a short-lived token paired with MFA closes most of the exposure window that static keys leave open.<\/li>\n<\/ul>\n<p>Larger organizations increasingly skip individual IAM user MFA altogether in favor of enforcing it at the identity provider level, which is worth considering if you\u2019re past a few dozen accounts.<\/p>\n<h2 id=\"troubleshooting-mfa-clock-drift-lost-devices-and-resyncing\"><span class=\"ez-toc-section\" id=\"Troubleshooting_MFA_Clock_Drift_Lost_Devices_and_Resyncing\"><\/span>Troubleshooting MFA: Clock Drift, Lost Devices, and Resyncing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>TOTP codes fail most often because of clock drift, not user error. If a virtual MFA device stops accepting codes even though they look correct, the device\u2019s internal clock has likely fallen out of sync with AWS\u2019s servers, a known limitation of the RFC 6238 standard itself.<\/p>\n<ol>\n<li>Confirm the phone or authenticator app\u2019s time is set to automatic, not manual.<\/li>\n<li>Run <code>resync-mfa-device<\/code> with two consecutive codes generated a few seconds apart to realign the device.<\/li>\n<li>If a device is lost or stolen, sign in using a registered backup device immediately and deregister the missing one.<\/li>\n<li>If no backup device exists, account recovery requires identity verification through AWS support, which can take days.<\/li>\n<\/ol>\n<p>That last point is why registering a second device matters more than it seems. Adding or removing an MFA device typically requires MFA from an existing device first, so a single lost phone with no backup can lock you out of your own remediation path. Plan a break-glass procedure, ideally a hardware token stored in a safe, before you need it.<\/p>\n<h2 id=\"how-logmeonces-passwordless-mfa-complements-aws-iam\"><span class=\"ez-toc-section\" id=\"How_LogMeOnces_Passwordless_MFA_Complements_AWS_IAM\"><\/span>How LogMeOnce\u2019s Passwordless MFA Complements AWS IAM<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>AWS IAM handles authentication into the AWS console and APIs, but most organizations run MFA across dozens of other systems too. Logmeonce builds passwordless MFA and single sign-on tools designed to centralize that sprawl, pairing FIDO-based authentication with identity management that extends beyond a single cloud provider. For teams already running IAM Identity Center or a federated identity provider, a centralized passwordless layer reduces the number of places employees register separate MFA devices in the first place.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/media.babylovegrowth.ai\/blog-images\/organization-6456\/1790165332207_How-LogMeOnce-s-Passwordless-MFA-Complements-AWS-IAM-overview-diagram.jpeg\" alt=\"How LogMeOnce&#039;s Passwordless MFA Complements AWS IAM \u2014 overview diagram\" title=\"\"><\/p>\n<h2 id=\"why-phishing-resistant-mfa-should-be-the-default-not-the-upgrade\"><span class=\"ez-toc-section\" id=\"Why_Phishing-Resistant_MFA_Should_Be_the_Default_Not_the_Upgrade\"><\/span>Why Phishing-Resistant MFA Should Be the Default, Not the Upgrade<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Most organizations still treat passkeys and security keys as the advanced option and TOTP as the default. That ordering is backward. TOTP was a real improvement over passwords alone, but it still asks a human to copy a code, which means it can still be phished. Security keys remove that step entirely. If you\u2019re setting up MFA for a new team today, start with FIDO and only fall back to virtual apps where hardware isn\u2019t practical yet. Pair that with centralized identity and an actual recovery plan, not an assumption that someone will remember their backup device.<\/p>\n<blockquote>\n<p><em>\u2014 Mike<\/em><\/p>\n<\/blockquote>\n<h2 id=\"sources\"><span class=\"ez-toc-section\" id=\"Sources\"><\/span>Sources<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li><a href=\"https:\/\/aws.amazon.com\/iam\/features\/mfa\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Multi-Factor Authentication (MFA) for IAM<\/a><\/li>\n<li><a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc6238\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">RFC 6238 &#8211; TOTP: Time-Based One-Time Password Algorithm<\/a><\/li>\n<\/ul>\n<h2 id=\"faq\"><span class=\"ez-toc-section\" id=\"FAQ\"><\/span>FAQ<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3 id=\"how-is-mfa-used-in-iam\"><span class=\"ez-toc-section\" id=\"How_Is_MFA_Used_in_IAM\"><\/span>How Is MFA Used in IAM?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>MFA in IAM adds a second identity check, beyond a password or access key, before granting access to the AWS console or APIs. It applies to the root user, individual IAM users, and can be enforced through policy conditions across an account. AWS supports passkeys, security keys, virtual TOTP apps, and hardware tokens as the underlying methods.<\/p>\n<h3 id=\"how-do-i-set-up-aws-multi-factor-authentication-in-iam\"><span class=\"ez-toc-section\" id=\"How_Do_I_Set_Up_AWS_Multi-Factor_Authentication_in_IAM\"><\/span>How Do I Set Up AWS Multi-Factor Authentication in IAM?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In the IAM console, go to a user\u2019s security credentials, choose \u201cAssign MFA device,\u201d and pick a passkey, security key, or virtual authenticator app. For a virtual app, scan the QR code and enter two consecutive codes to confirm the setup, following the console steps AWS documents. Root user MFA must go through the console; there\u2019s no CLI or API path for it.<\/p>\n<h3 id=\"what-is-the-difference-between-iam-and-sso\"><span class=\"ez-toc-section\" id=\"What_Is_the_Difference_Between_IAM_and_SSO\"><\/span>What Is the Difference Between IAM and SSO?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>IAM manages individual users, roles, and permissions inside a single AWS account. Single sign-on, typically through IAM Identity Center or a federated identity provider, lets one set of credentials and one MFA registration grant access across multiple AWS accounts and applications. Larger organizations generally move to SSO to avoid registering MFA separately for every account a person touches.<\/p>\n<h3 id=\"where-do-i-find-my-aws-mfa-code\"><span class=\"ez-toc-section\" id=\"Where_Do_I_Find_My_AWS_MFA_Code\"><\/span>Where Do I Find My AWS MFA Code?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Your MFA code comes from whichever device you registered: a virtual authenticator app generates a six-digit TOTP code that refreshes every 30 seconds, a hardware token displays its own rotating code, and a security key or passkey doesn\u2019t show a code at all since it authenticates directly through your browser or device. If a virtual app\u2019s codes stop working, the device has likely drifted out of sync and needs a <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc6238\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">resync<\/a>.<\/p>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Actionable MFA plan for security teams: adopt FIDO passkeys in AWS IAM, register backup devices, use console only root setup, and resync TOTP.<\/p>\n","protected":false},"author":0,"featured_media":248352,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-248350","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-logmeonce"],"acf":[],"_links":{"self":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts\/248350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/comments?post=248350"}],"version-history":[{"count":1,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts\/248350\/revisions"}],"predecessor-version":[{"id":248351,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts\/248350\/revisions\/248351"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/media\/248352"}],"wp:attachment":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/media?parent=248350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/categories?post=248350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/tags?post=248350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}