S3 offers two features that will require MFA has additional layer of security.
MFA Delete will require the bucket owner to authenticate with two forms of authentication when
Changing the versioning state of your bucket
Permanently deleting an object version
MFA-protected API access is configured via IAM policies, where you can specify which API operations a user is allowed to call and those where user needs to be authenticated with AWS multi-factor authentication (MFA) before you allow them to perform particularly sensitive actions.