Cognito identity pools should only allow authenticated identities

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Description

Cognito identity pools should not allow unauthenticated identities to assume IAM roles. When this parameter is enabled, it allows anonymous users to access AWS resources through the identity pool, which can introduce security risks by providing unauthorized access to your AWS environment.

Remediation

Set the AllowUnauthenticatedIdentities parameter to false when creating or updating Cognito identity pools. For guidance on managing identity pool authentication settings, refer to the Amazon Cognito Identity Pools documentation.