IAM users with a console password and no MFA device
What does ZopNight detect here?
ZopNight flags an IAM user who can sign in to the AWS Management Console with a password but has no MFA device registered. Users with only access keys are ignored, since console MFA does not apply to them. AWS lets each IAM user register up to 8 MFA devices, and the finding carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-083 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | console access and no MFA |
| Source | ZopNight |
| Permissions used | iam:ListUsers · iam:GetLoginProfile · iam:ListMFADevices · iam:GenerateCredentialReport · iam:GetCredentialReport |
Where it applies
A password alone is one phishing email away from the console
An IAM user with a console password and no second factor can be taken over by anyone who learns that password, whether through phishing, reuse from another breach or a shared spreadsheet. MFA closes that gap by requiring something the attacker does not have.
AWS recommends phishing-resistant MFA such as passkeys and security keys where possible, and each IAM user can register up to eight MFA devices of any type, so a lost device does not have to mean a locked-out user.
Finding console users without MFA
The credential report shows both facts side by side. Look for rows where password_enabled is
TRUE and mfa_active is FALSE:
aws iam generate-credential-reportaws iam get-credential-report --query 'Content' --output text | base64 --decode \ | cut -d, -f1,4,8For a single user, aws iam get-login-profile --user-name my-user confirms a console password
exists (it returns NoSuchEntity if not), and aws iam list-mfa-devices --user-name my-user
returns an empty list when no device is registered.
Both conditions have to be true
ZopNight records two facts for each IAM user during discovery: whether the user has console access and whether MFA is enabled. The rule fires only when console access is on and MFA is off. That keeps the focus on human sign-ins rather than service users.
Users who are not flagged
A user without a console password, typically a programmatic user with access keys only, is never flagged here; long-lived keys are covered by IAM User Access Key Older Than 90 Days. If either fact is missing for a user, no finding is produced. The root user is handled separately by Root Account MFA Not Enabled.
Security value, not savings
The finding has a $0 saving. It is rated high because console access is interactive and often broadly privileged.
Getting every console user onto MFA
- Contact each flagged user and have them register a device from the IAM console under Security credentials. A FIDO2 security key or passkey is the strongest choice; an authenticator app is acceptable.
- Have the user sign out and back in to confirm the device works.
- Enforce it with an IAM policy that denies most actions unless
aws:MultiFactorAuthPresentis true. The key is present only for short-term credentials, so write the condition so it does not block access-key calls you still depend on. - If a console password is not needed, delete it with
aws iam delete-login-profileinstead.