AWS S3 Bucket Has MFA Delete Enabled
Risk | Remediation Effort |
Low | Low |
This policy validates that a S3 bucket has MFA Delete enabled.
MFA delete ensures that all actions to delete objects in the bucket are authenticated with MFA. This provides an additional layer of security against malicious or accidental data loss.
Remediation
To remediate this, you must use a root account access key and execute the following command:
This cannot be performed from the AWS Console or in CloudFormation
Reference
AWS S3 Bucket MFA Delete documentation
Last updated