Let CLI users satisfy an MFA-required policy with aws sts get-session-token and MFA parameters
An AWS account administrator created an IAM group and applied the following managed policy to require that each individual user authenticate using multi-factor authentication: After implementing the policy, the administrator receives reports that users are unable to perform Amazon EC2 commands using the AWS CLI. What should the administrator do to resolve this problem while still enforcing multi-factor authentication? - 
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Long-term IAM user keys do not satisfy an MFA-required policy.
sts get-session-tokenwith MFA parameters returns short-term credentials whose requests are evaluated as MFA-present, so they pass the policy condition. The temporary access key, secret, and session token are used for the actual CLI calls.
An IAM group policy denies actions unless the request includes MFA (aws:MultiFactorAuthPresent), so users cannot run EC2 CLI commands with their long-term keys. The fix is for users to call aws sts get-session-token passing --serial-number and --token-code, producing temporary credentials that carry the MFA condition, then use those temporary credentials for subsequent CLI/API calls. This keeps MFA enforcement while restoring CLI access.
Setting aws:MultiFactorAuthPresent to true in the policy (option A)—that would weaken/break the enforcement, not help users authenticate. Or assuming federated SAML (C) or assume-role (D) is required; get-session-token is the direct CLI solution for an MFA-conditioned user policy.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The policy denies calls unless MFA is present, which long-term keys cannot satisfy.aws sts get-session-token with the MFA serial number and token code returns temporary credentials that are treated as MFA-authenticated; using those credentials for subsequent CLI calls satisfies the condition and restores EC2 command access without relaxing the policy.