You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过Terraform为IAM用户账户启用MFA?

Managing MFA for AWS IAM Users with Terraform

Absolutely! You can handle MFA setup for both individual IAM users and batches of users using Terraform. Let’s break down both scenarios clearly:

1. Enabling MFA for a Single IAM User

Yes, Terraform fully supports setting up MFA for a single IAM user. You’ll usually work with two key resources here:

  • aws_iam_virtual_mfa_device: Creates a virtual MFA device (for apps like Google Authenticator or Authy)
  • aws_iam_user_mfa_device: Links the MFA device to your user and completes activation (requires two consecutive codes from the device)

Here’s a complete, actionable example:

# Example IAM user (skip this if your user is already defined)
resource "aws_iam_user" "john_doe" {
  name = "john.doe"
  path = "/"
}

# Create a virtual MFA device tied to the user
resource "aws_iam_virtual_mfa_device" "john_mfa" {
  name                   = "mfa-john-doe"
  path                   = "/"
  virtual_mfa_device_name = "john-doe-virtual-mfa"
}

# Activate the MFA device for the user (requires two codes from the MFA app)
resource "aws_iam_user_mfa_device" "john_mfa_activated" {
  user_name       = aws_iam_user.john_doe.name
  serial_number   = aws_iam_virtual_mfa_device.john_mfa.serial_number
  authentication_code_1 = "123456" # Replace with first code from your MFA app
  authentication_code_2 = "654321" # Replace with second consecutive code
}

# Output the QR code URL so you can scan it with your MFA app
output "john_mfa_qr_code" {
  value = aws_iam_virtual_mfa_device.john_mfa.qr_code_png_url
}

Note: First scan the QR code URL output by Terraform into your MFA app, then grab two consecutive codes to fill in the authentication fields. For hardware MFA devices, skip the aws_iam_virtual_mfa_device resource and use the device’s serial number directly in aws_iam_user_mfa_device.

2. Enabling MFA for Multiple IAM Users (Bulk)

You can automate MFA setup across multiple users using Terraform’s for_each meta-argument to iterate over a list or map of user accounts. This ensures consistent MFA configuration across your team.

Here’s an example using a list of user names:

# Define a list of users to enable MFA for
variable "target_users" {
  type    = list(string)
  default = ["jane.doe", "bob.smith", "alice.jones"]
}

# Create the IAM users (skip if users already exist)
resource "aws_iam_user" "bulk_users" {
  for_each = toset(var.target_users)
  name     = each.value
  path     = "/"
}

# Create a virtual MFA device for each user
resource "aws_iam_virtual_mfa_device" "bulk_mfa_devices" {
  for_each = aws_iam_user.bulk_users
  name                   = "mfa-${each.value.name}"
  path                   = "/"
  virtual_mfa_device_name = "${each.value.name}-virtual-mfa"
}

# Activate MFA for each user (you'll need their respective MFA codes)
resource "aws_iam_user_mfa_device" "bulk_mfa_activated" {
  for_each           = aws_iam_user.bulk_users
  user_name          = each.value.name
  serial_number      = aws_iam_virtual_mfa_device.bulk_mfa_devices[each.key].serial_number
  authentication_code_1 = "USER_FIRST_CODE" # Replace with each user's first code
  authentication_code_2 = "USER_SECOND_CODE" # Replace with each user's second code
}

# Output all QR code URLs to share with users
output "all_mfa_qr_codes" {
  value = {
    for user in aws_iam_user.bulk_users : user.name => aws_iam_virtual_mfa_device.bulk_mfa_devices[user.name].qr_code_png_url
  }
}

Key notes for bulk setup:

  • Each user will need to scan their unique QR code and provide their two MFA codes. Share the output URLs with your team to complete this step.
  • For hardware MFA devices, replace the virtual device resource with a map that links each user to their device’s serial number, then use that map in the activation resource.

内容的提问来源于stack exchange,提问作者Mahela Wickramasekara

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:56:52