MFA: Password Policy Flashcards
Password policy
Set a minimum password length
Require specific character types:
- Including uppercase letters
- lowercase letters
- numbers
- non-alphanumeric characters
Allow all IAM users to change their own passwords
Require users to change their password after some time (password expiration).
Prevent password re-use
Multi Factor Authentication - MFA
Password you know + security device you own (Microsoft Authenticator)
MFA devices options
Virtual MFA device - multiple tokens on a single device:
- Google Authenticator (phone only)
- Authy (phone only)
Universal 2nd Factor (U2F) Security Key - multiple root and IAM users:
- YubiKey by Yubico (3rd party)
Hardware Key Fob MFA device:
- Provided by Gemalto (3rd party)
Hardware Key Fob MFA device for AWS GovCloud (US):
- Provided by SurePassID (3rd party)