I have a AWS Cognito user pool with several app clients. For two of those app clients I want to force users to identify with Multi-Factor Authentication (MFA). When signing in using any other app client, MFA should be disabled. If I enable MFA for the user pool, it affects all app clients.
In my research I've found that it is possible to create a custom authentication flow which I could implement MFA if the sign in request comes from a specific app client. But it would be nice if no custom implementation was needed. https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-authentication-flow.html#Custom-authentication-flow-and-challenges
Is there any other way than creating a custom authentication flow to only enable MFA for specific app clients?