AWS Security Agent adds email MFA support for pentesting
AWS Security Agent now supports email-based multi-factor authentication (MFA) for penetration testing, expanding coverage for applications using this authentication method. Previously, automated pentests could not handle email-based MFA because the agent couldn't intercept messages. This new capability allows customers to test applications with email-based authentication by routing MFA emails to the agent, which automatically extracts codes or links to complete authentication without storing credentials. The feature is available in all supported AWS Regions and complements existing TOTP support.
- →Email-based MFA support for penetration testing
- →Automated MFA code extraction
- →Unified MFA testing solution
- →Availability and setup
Features (1) ›
- Email-based MFA support for penetration testing
AWS Security Agent now supports penetration testing for applications that use email-based multi-factor authentication (MFA). This enhancement allows the agent to intercept and process one-time codes or verification links sent via email to complete authentication during pentests.
Enhancements (2) ›
- Automated MFA code extraction
The agent automatically reads forwarded MFA emails, extracts the necessary code or link, and submits it to complete authentication. This process does not involve storing email account credentials, ensuring a strong privacy posture.
- Unified MFA testing solution
This capability complements existing Time-based One-Time Password (TOTP) support, providing customers with a unified solution for testing applications across multiple MFA methods.
Notes (1) ›
- Availability and setup
This feature is available in all AWS Regions where AWS Security Agent is supported. Customers can use a forwarding rule in their email provider to route MFA emails to a unique forwarding address generated by the agent per credential.
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-agent-mfa/
Related releases
- Terraform AWS Provider v6.60.0 Adds New Resources and Fixes Bugs Terraform AWS Provider Releases ·
- Amazon S3 enhances access denied errors with specific policy ARNs AWS What's New ·
- OpenAI Daybreak Red and Blue Cyber Defense Models Now on Amazon Bedrock AWS What's New ·
- AppFolio Transforms Data Streaming with Amazon MSK Express Brokers AWS Big Data Blog ·
- AWS IAM Role Manager Automates Service Role Setup AWS What's New ·
- Amazon Quick Integrates Microsoft Purview for Data Loss Prevention AWS What's New ·