terraform-aws-iam icon indicating copy to clipboard operation
terraform-aws-iam copied to clipboard

fix!: Defaults `false` for `enable_mfa_enforcement` for IAM groups

Open claytonchew opened this issue 6 months ago β€’ 3 comments

Description

Resolves #509

Defaults enable_mfa_enforcement to false as it should be an opt-in feature.

Motivation and Context

Users migrating from older version (example version 5.3.1) to current version may find that IAM groups users with attach_iam_self_management_policy set to true suddenly lose access to their consoles, which can cause more harm than good.

Breaking Changes

This change should maintain backward compatibility for users migrating from versions prior to 5.14.3. However, users having versions 5.14.3 and beyond may find that MFA enforcement no longer being enforced by default, requiring enable_mfa_enforcement to be explicitly set to true.

How Has This Been Tested?

  • [ ] I have updated at least one of the examples/* to demonstrate and validate my change(s)
  • [ ] I have tested and validated these changes using one or more of the provided examples/* projects
  • [ ] I have executed pre-commit run -a on my pull request

claytonchew avatar Aug 13 '24 01:08 claytonchew