Skip to main content

πŸ’Ό IA-2(1) Multi-factor Authentication to Privileged Accounts (L)(M)(H)

Description​

Implement multi-factor authentication for access to privileged accounts.

IA-2 (1) Additional FedRAMP Requirements and Guidance:

Guidance: Multi-factor authentication to subsequent components in the same user domain is not required.

Requirement: According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL).

Requirement: Multi-factor authentication must be phishing-resistant.

Similar​

  • Sections
    • /frameworks/fedramp-high-security-controls/ia/02/01
  • Internal
    • ID: dec-c-b969b124

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό IA-2(1) Multi-factor Authentication to Privileged Accounts (L)(M)(H)2

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (2)​

PolicyLogic CountFlags
πŸ“ AWS Account Root User Hardware MFA is not enabled. 🟒🟒 x3
πŸ“ AWS IAM User MFA is not enabled for all users with console password 🟒1🟒 x6