Enforce AWS MFA for IAM Users with a Deny-by-Default Policy (and Safe Exceptions)
Still have legacy IAM users? This guide shows how to enforce MFA with a simple explicit-deny policy that blocks all actions unless MFA is present—yet preserves just enough access to enroll devices or obtain temporary session tokens. We cover rollout options, SCP usage, exception patterns, monitoring, and common pitfalls.