Skip to main content

πŸ“ Google Accounts are not configured with MFA 🟒

  • Contextual name: πŸ“ Google Accounts are not configured with MFA 🟒
  • ID: /ce/ca/google/iam/multi-factor-authentication
  • Located in: πŸ“ Google IAM

Flags​

Our Metadata​

  • Policy Type: COMPLIANCE_POLICY
  • Policy Category:
    • SECURITY

Similar Policies​

Description​

Open File

Description​

Setup multi-factor authentication for Google Cloud Platform accounts.

Rationale​

Multi-factor authentication requires more than one mechanism to authenticate a user. This secures user logins from attackers exploiting stolen or weak credentials.

Audit​

From Google Cloud Console​

For each Google Cloud Platform project, folder, or organization:

  1. Identify non-service accounts.
  2. Manually verify that multi-factor authentication for each account is set.

Default Value​

By default, multi-factor authentication is not set.

References​

  1. https://cloud.google.com/solutions/securing-gcp-account-u2f
  2. https://support.google.com/accounts/answer/185839

Remediation​

Open File

Remediation​

From Google Cloud Console​

For each Google Cloud Platform project:

  1. Identify non-service accounts.
  2. Setup multi-factor authentication for each account.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS GCP v3.0.0 β†’ πŸ’Ό 1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service Accounts - Level 1 (Manual)1
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Multi-Factor Authentication (MFA) Implementation16