AWS S3 Bucket Has MFA Delete Enabled
Last updated
Last updated
This policy validates that a S3 bucket has MFA Delete enabled.
MFA delete ensures that all actions to delete objects in the bucket are authenticated with MFA. This provides an additional layer of security against malicious or accidental data loss.
Remediation
To remediate this, you must use a root account access key and execute the following command:
This cannot be performed from the AWS Console or in CloudFormation
Reference
AWS S3 Bucket MFA Delete documentation
Risk
Remediation Effort
Low
Low