Trying to set up authentication with Cognito in my application and my use case requires a MFA on a per-user basis. That said, upon creating the respective user pool, I've configured the MFA to be Optional and selected TOTP as a potential MFA option. So far so good and with the user pool in place I'm creating a user for whom (after creation) I'm trying to set the preferred MFA method to TOTP in my Kotiln application, so the next time the user signs in, he gets a prompt to setup his TOTP-based MFA.
According to the API docs, this should be possible like so: https://docs.aws.amazon.com/cognito-user-identity-pools/latest/APIReference/API_AdminSetUserMFAPreference.html
The code snapshot looks like this:
val cognitoClient: CognitoIdentityProviderClient = CognitoIdentityProviderClient.builder()
.region(Region.US_EAST_1)
...
.build()
val mfaPreferenceRequest = AdminSetUserMfaPreferenceRequest.builder()
.userPoolId("us-east-1-some-pool-id")
.username("test")
.softwareTokenMfaSettings(
SoftwareTokenMfaSettingsType.builder()
.enabled(true)
.preferredMfa(true)
.build()
).build()
cognitoClient.adminSetUserMFAPreference(mfaPreferenceRequest)
When called though, I'm getting the following exception/stacktrace
InvalidParameterException: User does not have delivery config set to turn on SOFTWARE_TOKEN_MFA.
Any clues on what might be causing this?