Queries the MFA device list of a user. Each user can have a maximum of two MFA devices.
Operation description
This topic provides an example on how to query the MFA device list of the user u-00q8wbq42wiltcrk****. The response shows that the user has one MFA device named Alice-MFA1.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cloudsso:ListMFADevicesForUser |
list |
*User
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| DirectoryId |
string |
Yes |
The directory ID. |
d-00fc2p61**** |
| UserId |
string |
Yes |
The user ID. |
u-00q8wbq42wiltcrk**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response. |
||
| RequestId |
string |
The request ID. |
8B9982ED-FD0D-5622-8EA0-7B768685DCE7 |
| TotalCounts |
integer |
The total number of MFA devices. |
1 |
| MFADevices |
array<object> |
The MFA device list. |
|
|
object |
The MFA device list. |
||
| DeviceType |
string |
The MFA device type. Valid values:
|
TOTP |
| EffectiveTime |
string |
The effective period. The time is in UTC and follows the RFC 3339 format (YYYY-MM-DDTHH:mm:ssZ). |
2021-10-29T09:14:06Z |
| DeviceId |
string |
The MFA device ID. |
mfa-00ujhet8pycljj7j**** |
| UserId |
string |
The user ID. |
u-00q8wbq42wiltcrk**** |
| DeviceName |
string |
The MFA device name. |
Alice-MFA1 |
| LastUseTime |
string |
The last time the MFA device was used. |
2026-08-12T07:26:12Z |
Examples
Success response
JSON format
{
"RequestId": "8B9982ED-FD0D-5622-8EA0-7B768685DCE7",
"TotalCounts": 1,
"MFADevices": [
{
"DeviceType": "TOTP",
"EffectiveTime": "2021-10-29T09:14:06Z",
"DeviceId": "mfa-00ujhet8pycljj7j****",
"UserId": "u-00q8wbq42wiltcrk****",
"DeviceName": "Alice-MFA1",
"LastUseTime": "2026-08-12T07:26:12Z"
}
]
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.