You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Cognito强制MFA用户池间迁移失败问题求助

AWS Cognito强制MFA用户池迁移失败问题

问题背景

需要将原强制开启MFA的AWS Cognito用户池中的用户迁移到新的强制开启MFA的用户池,已创建UserMigration_Authentication类型的Lambda触发器,触发器可正常触发并返回以下响应:

"response": {
      "userAttributes": {
        "email": "test@example.com",
        "email_verified": "true",
        "phone_number": "+917023433333",
        "phone_number_verified": "true"
      },
      "forceAliasCreation": null,
      "finalUserStatus": "CONFIRMED",
      "messageAction": "SUPPRESS",
      "desiredDeliveryMediums": null
}

触发时的事件对象如下:

{
    "version": "1",
    "triggerSource": "UserMigration_Authentication",
    "region": "us-east-1",
    "userPoolId": "us-east-1_newPoold",
    "userName": "test@example.com",
    "callerContext": {
        "awsSdkVersion": "aws-sdk-unknown-unknown",
        "clientId": "dddaio06kd1ls20sss5cpgddd"
    },
    "request": {
        "password": "Test@123",
        "validationData": {},
        "userAttributes": null
    },
    "response": {
        "userAttributes": null,
        "forceAliasCreation": null,
        "finalUserStatus": null,
        "messageAction": null,
        "desiredDeliveryMediums": null
    }
}

当前现状:将用户迁移到非强制MFA的用户池时,脚本可正常工作,用户成功创建;但迁移到强制MFA的用户池时流程失败,使用的Lambda代码基于Collaborne的Cognito用户池迁移实现。

问题原因与解决办法

核心原因

目标用户池强制开启MFA时,迁移流程需要满足额外的MFA验证要求:

  • 用户必须拥有已验证的联系方式(邮箱或手机号,对应属性email_verified/phone_number_verified为true)
  • 迁移后的用户需要启用MFA状态,且默认迁移逻辑未处理强制MFA场景下的用户状态同步

具体修复步骤

  1. 补充MFA相关用户属性
    在Lambda返回的userAttributes中添加mfa_enabled属性并设置为true,明确启用用户的MFA状态:

    "userAttributes": {
      "email": "test@example.com",
      "email_verified": "true",
      "phone_number": "+917023433333",
      "phone_number_verified": "true",
      "mfa_enabled": "true"
    }
    
  2. 同步原用户的MFA配置
    在Lambda逻辑中添加步骤:

    • 调用原用户池的AdminGetUser接口,获取用户的UserMFASettingList属性(记录原用户启用的MFA类型,如TOTP、短信)
    • 迁移完成后,调用目标用户池的AdminSetUserMFAPreference接口,将原用户的MFA设置同步到新用户
  3. 调整用户最终状态
    如果原用户未完成MFA验证(或无法同步MFA设备),不要将finalUserStatus设为CONFIRMED,改为RESET_REQUIRED,引导用户首次登录时完成MFA设置:

    "finalUserStatus": "RESET_REQUIRED"
    
  4. 检查用户池客户端配置
    确保目标用户池的客户端配置与强制MFA要求匹配:

    • 启用客户端的MFA强制选项
    • 确保客户端支持的OAuth流程兼容MFA验证

修改后的Lambda响应示例

{
  "response": {
    "userAttributes": {
      "email": "test@example.com",
      "email_verified": "true",
      "phone_number": "+917023433333",
      "phone_number_verified": "true",
      "mfa_enabled": "true"
    },
    "forceAliasCreation": null,
    "finalUserStatus": "CONFIRMED",
    "messageAction": "SUPPRESS",
    "desiredDeliveryMediums": ["SMS"]
  }
}

内容的提问来源于stack exchange,提问作者Sagar Kharche

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 05:06:26