Skip to main content
compliance · aws

IAM users with a console password and no MFA device

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags an IAM user who can sign in to the AWS Management Console with a password but has no MFA device registered. Users with only access keys are ignored, since console MFA does not apply to them. AWS lets each IAM user register up to 8 MFA devices, and the finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates IAM users with a console password and no MFA device.
Field Value
Rule IDsRC-083
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdconsole access and no MFA
SourceZopNight
Permissions usediam:ListUsers · iam:GetLoginProfile · iam:ListMFADevices · iam:GenerateCredentialReport · iam:GetCredentialReport

A password alone is one phishing email away from the console

An IAM user with a console password and no second factor can be taken over by anyone who learns that password, whether through phishing, reuse from another breach or a shared spreadsheet. MFA closes that gap by requiring something the attacker does not have.

AWS recommends phishing-resistant MFA such as passkeys and security keys where possible, and each IAM user can register up to eight MFA devices of any type, so a lost device does not have to mean a locked-out user.

Finding console users without MFA

The credential report shows both facts side by side. Look for rows where password_enabled is TRUE and mfa_active is FALSE:

Terminal window
aws iam generate-credential-report
aws iam get-credential-report --query 'Content' --output text | base64 --decode \
| cut -d, -f1,4,8

For a single user, aws iam get-login-profile --user-name my-user confirms a console password exists (it returns NoSuchEntity if not), and aws iam list-mfa-devices --user-name my-user returns an empty list when no device is registered.

Both conditions have to be true

ZopNight records two facts for each IAM user during discovery: whether the user has console access and whether MFA is enabled. The rule fires only when console access is on and MFA is off. That keeps the focus on human sign-ins rather than service users.

Users who are not flagged

A user without a console password, typically a programmatic user with access keys only, is never flagged here; long-lived keys are covered by IAM User Access Key Older Than 90 Days. If either fact is missing for a user, no finding is produced. The root user is handled separately by Root Account MFA Not Enabled.

Security value, not savings

The finding has a $0 saving. It is rated high because console access is interactive and often broadly privileged.

Getting every console user onto MFA

  1. Contact each flagged user and have them register a device from the IAM console under Security credentials. A FIDO2 security key or passkey is the strongest choice; an authenticator app is acceptable.
  2. Have the user sign out and back in to confirm the device works.
  3. Enforce it with an IAM policy that denies most actions unless aws:MultiFactorAuthPresent is true. The key is present only for short-term credentials, so write the condition so it does not block access-key calls you still depend on.
  4. If a console password is not needed, delete it with aws iam delete-login-profile instead.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·