Glossary

    Cognito Security

    Identity & Access

    Amazon Cognito handles customer identity for applications. It has two main components:

    User Pools (Authentication)

    • Managed user directory with sign-up, sign-in, and account recovery
    • Issues JWT tokens (ID token, access token, refresh token)
    • Built-in MFA (SMS, TOTP, email)
    • Advanced security features: compromised credential detection, adaptive authentication, bot detection
    • Social and enterprise federation (Google, Facebook, Apple, SAML, OIDC)

    Identity Pools (Authorization)

    • Exchange tokens for temporary AWS credentials via STS
    • Map authenticated and unauthenticated users to IAM roles
    • Fine-grained access to AWS resources per user

    Security Best Practices

    • Enable advanced security features for risk-based adaptive authentication
    • Configure strong password policies (length, complexity, expiration)
    • Use custom authentication flows (Lambda triggers) for additional validation
    • Implement token revocation for compromised sessions

    Related AWS Services

    Related Content

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.