terraform-aws-iam
terraform-aws-iam copied to clipboard
fix!: Defaults `false` for `enable_mfa_enforcement` for IAM groups
Description
Resolves #509
Defaults enable_mfa_enforcement
to false
as it should be an opt-in feature.
Motivation and Context
Users migrating from older version (example version 5.3.1) to current version may find that IAM groups users with attach_iam_self_management_policy
set to true
suddenly lose access to their consoles, which can cause more harm than good.
Breaking Changes
This change should maintain backward compatibility for users migrating from versions prior to 5.14.3. However, users having versions 5.14.3 and beyond may find that MFA enforcement no longer being enforced by default, requiring enable_mfa_enforcement
to be explicitly set to true
.
How Has This Been Tested?
- [ ] I have updated at least one of the
examples/*
to demonstrate and validate my change(s) - [ ] I have tested and validated these changes using one or more of the provided
examples/*
projects
- [ ] I have executed
pre-commit run -a
on my pull request