启用AWS S3桶MFA时遇DevPay与MFA互斥错误求助
Hey there, let's work through this error you're hitting when trying to enable MFADelete for your S3 bucket.
What's causing this error?
The error message "DevPay and Mfa are mutually exclusive authorization methods" means your AWS account is currently using the DevPay billing model—an older AWS pricing scheme. Unfortunately, S3's MFADelete feature (which adds an extra security layer for versioning operations) can't be used alongside DevPay; they’re incompatible by design.
Step-by-step solutions
- Confirm your billing model first: Check your AWS account's billing settings or reach out to AWS Support to verify if DevPay is enabled for your account.
- Switch to a standard billing model: DevPay is a legacy model, so you’ll need to transition to AWS’s modern billing options (like On-Demand, Reserved Instances, or Savings Plans). Once this transition is complete, the conflict between DevPay and MFADelete will be resolved.
- Re-run your versioning command: After switching billing models, execute your original command again—make sure your MFA token is valid and the syntax is correct:
aws s3api put-bucket-versioning --bucket ewiglife-mfa-testin --versioning-configuration Status=Enabled,MFADelete=Enabled --mfa "arn:aws:iam::xxxxxxxxxxxx:mfa/root-account-mfa-device xxxxxx"
Extra tips to keep in mind
- Ensure the user/role running the command has the
s3:PutBucketVersioningIAM permission. - MFADelete can only be enabled by the root account or an IAM user with explicit permissions to manage bucket versioning with MFA. Double-check your IAM policies if you’re using a non-root user.
内容的提问来源于stack exchange,提问作者Usman
相关产品推荐
相关产品推荐

