AWS Cognito - Enable MFA per user

Viewed 42

Trying to set up authentication with Cognito in my application and my use case requires a MFA on a per-user basis. That said, upon creating the respective user pool, I've configured the MFA to be Optional and selected TOTP as a potential MFA option. So far so good and with the user pool in place I'm creating a user for whom (after creation) I'm trying to set the preferred MFA method to TOTP in my Kotiln application, so the next time the user signs in, he gets a prompt to setup his TOTP-based MFA.

According to the API docs, this should be possible like so: https://docs.aws.amazon.com/cognito-user-identity-pools/latest/APIReference/API_AdminSetUserMFAPreference.html

The code snapshot looks like this:

val cognitoClient: CognitoIdentityProviderClient = CognitoIdentityProviderClient.builder()
      .region(Region.US_EAST_1)
      ...
      .build()

    val mfaPreferenceRequest = AdminSetUserMfaPreferenceRequest.builder()
      .userPoolId("us-east-1-some-pool-id")
      .username("test")
      .softwareTokenMfaSettings(
        SoftwareTokenMfaSettingsType.builder()
          .enabled(true)
          .preferredMfa(true)
          .build()
      ).build()

    cognitoClient.adminSetUserMFAPreference(mfaPreferenceRequest)

When called though, I'm getting the following exception/stacktrace

InvalidParameterException: User does not have delivery config set to turn on SOFTWARE_TOKEN_MFA.

Any clues on what might be causing this?

0 Answers
Related