Permissions
The Enforce MFA Is Enabled for AWS IAM Users policy pack requires 10 permissions:
iam:DeactivateMFADeviceiam:DeleteAccessKeyiam:DeleteLoginProfileiam:DeleteUseriam:DeleteUserPolicyiam:DeleteVirtualMFADeviceiam:DetachUserPolicyiam:ListAccessKeysiam:ListMFADevicesiam:RemoveUserFromGroup