π‘οΈ Oracle IAM User MFA is disabledπ’
- Contextual name: π‘οΈ IAM User MFA is disabledπ’
- ID:
/ce/ca/oracle/iam/user-mfa-disabled - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicβ
- π§ prod.logic.yamlπ’
- π Oracle IAM User
- π Oracle IAM User - object.extracts.yaml
- π§ͺ test-data.json
Similar Policiesβ
- Internal:
dec-x-b92b08f4
Similar Internal Rulesβ
| Rule | Policies | Flags |
|---|---|---|
| βοΈ dec-x-b92b08f4 | 1 |
Descriptionβ
Descriptionβ
This policy identifies Oracle IAM Users that do not have multifactor authentication (MFA) activated.
Rationaleβ
MFA adds a second authentication factor to the standard username and password sign-in flow. Requiring MFA for OCI IAM users reduces the likelihood that stolen, guessed, or reused passwords can be used to access the OCI Console.
Impactβ
Users without MFA are more exposed to credential theft, phishing, password spraying, and credential stuffing attacks. A compromised OCI IAM user can be used to view or change cloud resources according to the user's assigned policies, so interactive accounts should require an additional verification factor.
Auditβ
This policy flags an Oracle IAM User as
INCOMPLIANTif theLifecycle Statefield is set to ACTIVE and theMFA Statusfield is set to Deactivated.Users whose
Lifecycle Statefield is not set to ACTIVE are marked asINAPPLICABLE. Users with an empty or unexpectedMFA Statusvalue are marked asUNDETERMINED.
Remediationβ
Remediationβ
Enforce MFA from Oracle Cloud Consoleβ
- Sign in to the OCI Console.
- Open the navigation menu and select
Identity & Security.- Under
Identity, selectDomains.- Select the identity domain that contains the affected users.
- Open
Security, then selectSign-on policies.- If
Security Policy for OCI Consoleexists, open it and confirm that:
- The policy is activated.
- The OCI Console application is assigned to the policy.
- The
MFA for all usersrule is active.- The rule allows access, prompts for an additional factor, and sets MFA enrollment to
Required.- If the
Security Policy for OCI Consolepolicy does not exist or cannot be used, create a sign-on policy for OCI Console access:
- Select
Create sign-on policy.- Add a sign-on rule for the users or groups that require OCI Console access.
- Set the rule action to allow access.
- Enable
Prompt for an additional factor.- Set MFA enrollment to
Required.- Add the OCI Console application to the policy.
... see more