NOTE: You can configure MFA capabilities in IAM Identity Center when your identity source is configured with IAM Identity Center’s identity store, AWS Managed Microsoft AD, or AD Connector. MFA in IAM Identity Center is currently not supported for external identity providers.
To configure MFA device enforcement for your users
- Open the IAM Identity Center console.
- In the left navigation pane, choose Settings.
- On the Settings page, choose the Authentication tab.
- In the Multi-factor authentication section, choose Configure.
- On the Configure multi-factor authentication page, under If a user does not yet have a registered MFA device choose the option Require them to register an MFA device at sign in.
- Choose Save changes.