Add an aws:MultiFactorAuthPresent condition to the role's trust policy for MFA-gated assumption
A company has two AWS accounts: Account A and Account B. Account A has an IAM role that IAM users in Account B assume when they need to upload sensitive documents to Amazon S3 buckets in Account A. A new requirement mandates that users can assume the role only if they are authenticated with multi-factor authentication (MFA). A security engineer must recommend a solution that meets this requirement with minimum risk and effort. Which solution should the security engineer recommend?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Role assumption is governed by the role's trust policy, so the MFA condition belongs there (B). A permissions policy (A) controls what the role can do after assumption, not who can assume it. A session policy (C) is passed at assumption time and further restricts, but the gate must be in the trust policy. An S3 bucket policy (D) controls bucket access, not role assumption. B is correct.
IAM users in Account B assume a role in Account A to upload documents, and the new rule requires MFA. The trust policy of the role controls who can assume it, so add an aws:MultiFactorAuthPresent condition (or aws:MultiFactorAuthAge) to that trust policy—then only principals authenticated with MFA can assume the role. This is the minimal-risk, minimal-effort change and sits at the correct policy layer.
Putting the condition in the role's permissions policy (A)—that restricts post-assumption actions, not the act of assuming, so MFA would not be enforced at assumption. Using a session policy (C)—it can further narrow permissions but the MFA gate must be in the trust policy that decides who may assume. An S3 bucket policy (D) governs bucket access, irrelevant to role assumption.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.