解決 Amazon 雲端服務 (AWS) 輸入 MFA 驗證碼,一直驗證失敗的問題

登入 Amazon 雲端服務 (AWS) 輸入 MFA 驗證碼,一直驗證失敗的問題。直接重設新密碼解決。



問題狀況:

雖然輸入正確的密碼、也輸入了兩階段驗證 APP 提供的 MFA (Multi-Factor Authentication,多因子驗證) 驗證碼,但是一直顯示驗證碼錯誤、需要重複出現密碼的狀況。

我點選了「MFA 疑難排解」按鈕,選擇重新同步 (Re-sync with AWS Servers) 選項,但仍然無效。我再次輸入不同時間產生的 MFA 驗證碼,依然無法通過驗證。改成選擇使用不同驗證因子 (Sign in using alternative factors) 選項,依舊沒有解決問題。



解決方式:

點選忘記密碼,使用新的密碼登入,再輸入兩階段驗證 APP 提供的 MFA 驗證碼。就可以順利登入。

補充說明:官方建議使用「不同驗證因子」 (Sign in using alternative factors) 選項,「透過電子郵件和電話號碼驗證身份 → 登入後在安全憑證頁面停用失效的 MFA 裝置 → 最後重新設定新的 MFA 裝置。」

相關參考資料:

1. 一開始以為是兩階段驗證 APP 的問題,這篇文章提到手機版 APP 需要注意時間同步。但是我使用的是桌機板兩階段驗證 APP,所以不是這個原因。

2. 兩年前 reddit 上有人遇到同樣問題 AWS Account MFA Not Working? : r/aws ,AWS 客服提供聯繫表單的連結 Lost or unusable Multi-Factor Authentication (MFA) device

我直接附上很像是 AI 的回覆,供大家參考:

I understand you're having trouble signing into your AWS root account with your Authy MFA app, and that the resync and lost device options haven't resolved the issue.


If your AWS account has multiple root multi-factor authentication (MFA) devices activated, then you can use an alternate MFA device that's registered on the account to sign in.


For steps on how to regain access to your AWS account when your root user MFA device is not working, please see the self-serving method at "What if my MFA device stops working": https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html


Another helpful blog which explains the process of troubleshooting MFA through images is available at the following AWS security blog: https://aws.amazon.com/blogs/security/reset-your-aws-root-accounts-lost-mfa-device-faster-by-using-the-aws-management-console/


In case you run into blockers in following the steps for the self-serving method, the following suggestions may help:


If you receive an error when you choose Sign In Using Alternative Factors, then try again on a different browser or use a private/incognito window.


Clear your browser's cache and cookies, then refresh the page

Try another supported browser: https://aws.amazon.com/console/faq-console


Make sure JavaScript is turned on

If you don't have access to an alternate MFA device, then try to sign in with the help of an AWS Identity and Access Management (IAM) user with admin permissions and access to billing to update your MFA settings.


For more information, see "How do I update my telephone number to reset my lost MFA device?": https://repost.aws/knowledge-center/reset-mfa-device


Additional troubleshooting documentation is available at:

https://docs.aws.amazon.com/signin/latest/userguide/troubleshooting-sign-in-issues.html#credentials-not-working

https://aws.amazon.com/premiumsupport/knowledge-center/sign-in-account/


By following these self-serving methods, you should be able to regain access to your AWS account and restore your MFA functionality.


This response might contain information related to security, a nuanced topic. You should verify the response using informed human judgement. Visit Security in AWS Support for more details.

https://docs.aws.amazon.com/awssupport/latest/user/security.html

中文翻譯
我了解您在使用 Authy MFA 應用程式登入 AWS root 帳戶時遇到問題,而且重新同步和遺失裝置選項都無法解決此問題。

如果您的 AWS 帳戶已啟用多個 root 多重要素驗證 (MFA) 裝置,那麼您可以使用帳戶上註冊的其他 MFA 裝置來登入。

關於當您的 root 使用者 MFA 裝置無法運作時,如何重新取得 AWS 帳戶存取權限的步驟,請參閱「如果我的 MFA 裝置停止運作該怎麼辦」的自助方法:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html

另一篇有用的部落格文章透過圖片說明了 MFA 疑難排解的流程,可在以下 AWS 安全性部落格取得:https://aws.amazon.com/blogs/security/reset-your-aws-root-accounts-lost-mfa-device-faster-by-using-the-aws-management-console/

如果您在遵循自助方法的步驟時遇到障礙,以下建議可能有幫助:

如果您在選擇「使用替代要素登入」時收到錯誤訊息,請在不同的瀏覽器上重試或使用無痕/私密瀏覽視窗。

清除瀏覽器的快取和 cookie,然後重新整理頁面
嘗試其他支援的瀏覽器:https://aws.amazon.com/console/faq-console
確保已開啟 JavaScript

如果您無法存取其他 MFA 裝置,那麼請嘗試透過具有管理員權限和帳單存取權限的 AWS Identity and Access Management (IAM) 使用者協助登入,以更新您的 MFA 設定。
如需更多資訊,請參閱「如何更新我的電話號碼以重設遺失的 MFA 裝置?」:https://repost.aws/knowledge-center/reset-mfa-device

其他疑難排解文件可在以下位置取得:

https://docs.aws.amazon.com/signin/latest/userguide/troubleshooting-sign-in-issues.html#credentials-not-working
https://aws.amazon.com/premiumsupport/knowledge-center/sign-in-account/
透過遵循這些自助方法,您應該能夠重新取得 AWS 帳戶的存取權限並恢復 MFA 功能。

此回應可能包含與安全性相關的資訊,這是一個需要細緻處理的主題。您應該使用具備相關知識的人工判斷來驗證此回應。請造訪 AWS Support 中的安全性以了解更多詳情。
https://docs.aws.amazon.com/awssupport/latest/user/security.html

留言