Cognito identity pools should only allow authenticated identities

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Description

Cognito identity pools should not allow unauthenticated identities to assume IAM roles. When this parameter is enabled, it allows anonymous users to access AWS resources through the identity pool, which can introduce security risks by providing unauthorized access to your AWS environment.

Remediation

Set the AllowUnauthenticatedIdentities parameter to false when creating or updating Cognito identity pools. For guidance on managing identity pool authentication settings, refer to the Amazon Cognito Identity Pools documentation.