Which TWO are valid ways to authenticate an IAM user?
Trap 1: SSL/TLS certificate
SSL/TLS certificates are not recognized by the IAM user authentication process. While AWS services such as API Gateway can use client certificates for mutual TLS, IAM itself never validates a certificate as proof of identity for console or API access. Server certificates in IAM are used only to enable HTTPS on your custom domain, which authenticates the server, not the user. Thus, a certificate cannot substitute for an IAM password or access key.
Trap 2: MFA token
An MFA token provides a one-time code that must be combined with a primary credential—either a password for console sign-in or an access key for programmatic requests—to complete authentication. AWS treats MFA as an additional security factor designed to protect against credential theft, not as a standalone authentication method. While IAM policies can require MFA as a condition, the token itself never initiates an authenticated session. Therefore, an MFA token alone cannot authenticate an IAM user.
Trap 3: SSH key pair
SSH key pairs are primarily used to authenticate to EC2 instances over SSH, not to the AWS account itself. Although IAM supports uploading SSH public keys for use with AWS CodeCommit over SSH, this is a service-specific repository authentication mechanism, not a general IAM user authentication credential. An SSH key pair does not sign AWS API requests or allow console access. Therefore, it is not a valid way to authenticate an IAM user to AWS.
- A
SSL/TLS certificate
Why it fails: SSL/TLS certificates are not recognized by the IAM user authentication process. While AWS services such as API Gateway can use client certificates for mutual TLS, IAM itself never validates a certificate as proof of identity for console or API access. Server certificates in IAM are used only to enable HTTPS on your custom domain, which authenticates the server, not the user. Thus, a certificate cannot substitute for an IAM password or access key.
- B
MFA token
Why it fails: An MFA token provides a one-time code that must be combined with a primary credential—either a password for console sign-in or an access key for programmatic requests—to complete authentication. AWS treats MFA as an additional security factor designed to protect against credential theft, not as a standalone authentication method. While IAM policies can require MFA as a condition, the token itself never initiates an authenticated session. Therefore, an MFA token alone cannot authenticate an IAM user.
- C
Password
An IAM user password is the primary authentication factor for the AWS Management Console, entered together with the account ID or alias at the sign-in page. This password is stored as a login profile for the IAM user and can be rotated manually by the user or administratively by an account administrator. It functions as a persistent credential that grants full access to the console session. This is one of the two standard ways to authenticate an IAM user.
- D
SSH key pair
Why it fails: SSH key pairs are primarily used to authenticate to EC2 instances over SSH, not to the AWS account itself. Although IAM supports uploading SSH public keys for use with AWS CodeCommit over SSH, this is a service-specific repository authentication mechanism, not a general IAM user authentication credential. An SSH key pair does not sign AWS API requests or allow console access. Therefore, it is not a valid way to authenticate an IAM user to AWS.
- E
Access keys (access key ID and secret access key)
An IAM user access key consists of an access key ID and a secret access key, which together are used with AWS Signature Version 4 to sign programmatic requests to the AWS API and CLI. These keys are long-term credentials tied to the IAM user and can be created, rotated, or deactivated by the user or an administrator. Unlike a password, access keys do not permit console login. They are the standard authentication method for all programmatic AWS access.