The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →AWS now requires multi-factor authentication (MFA) for the root user of every AWS account type: standalone accounts, Organizations management accounts and member accounts. A root user without MFA must register it within 35 days of the first sign-in attempt to the AWS Management Console. Enforcement was introduced in stages rather than on one date for every customer, so administrators should follow the notices shown for each account.
What changed, and when
AWS announced in October 2023 that it would require MFA for its most privileged identities, beginning with Organizations management-account root users. The rollout then widened:
| Period | Change |
|---|---|
| October 2023 | AWS announced mandatory MFA plans for privileged root users. |
| May 2024 | Enforcement began for management-account root users, initially in larger environments. |
| June 2024 | AWS introduced FIDO2 passkeys and announced expansion to standalone accounts. |
| July 2024 onward | Standalone-account root users entered a gradual rollout with reminders and a grace period. |
| Spring 2025 plan | AWS planned gradual enforcement for Organizations member-account root users where centralized root access management was not enabled, with advance notifications. |
| Current IAM guidance | Standalone, management and member accounts all require root-user MFA; users without it have 35 days after their first console sign-in attempt to register. |
The exact activation date can differ by account. Check AWS sign-in notices and the current account guidance rather than assuming a single organization-wide deadline.
Is MFA required for AWS root users?
Yes. AWS IAM documentation states: “All AWS account types (standalone, management, and member accounts) require MFA to be configured for their root user.” The requirement concerns root-user console sign-in. It does not mean that every IAM, workforce or federated user was newly placed under this particular rollout; those identities still need controls appropriate to their own access paths.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the 35-day window means
If root MFA is not already configured, AWS gives the root user 35 days from the first sign-in attempt to the Management Console to register an MFA device. The window is tied to that sign-in event, not necessarily to the date AWS began its broad programme. Follow the account-specific prompts and notices because staged deployment can affect when enforcement is encountered.
What AWS reported about early results
AWS described the initial programme as successful, but these are AWS-reported figures rather than independently audited measurements:
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- AWS said enabling MFA prevented more than 99% of password-related attacks in 2024. This figure does not represent all cyberattacks.
- AWS said customer registration rates for phishing-resistant MFA increased by more than 100% after FIDO2 passkey support launched in June 2024; the announcement did not provide a denominator.
- More than 750,000 AWS root users enabled MFA between April and October 2024.
AWS Principal Product Manager Arynn Crow described MFA as “a foundational component in overall account security” and one of the simplest and most effective ways to help prevent unauthorized access.
Choosing an MFA method
AWS supports FIDO2 passkeys, FIDO-certified security keys and other supported MFA methods. It recommends a passkey or security key where possible because these methods are more resistant to phishing.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Method | Security and operational characteristics | Best fit |
|---|---|---|
| Syncable FIDO2 passkey | Uses public-key authentication designed to resist phishing. A credential provider may back it up and synchronize it, so the provider’s vault access and account-recovery model become part of your security decision. | Teams wanting strong phishing resistance with convenient recovery across approved devices. |
| FIDO2 hardware security key | The credential is bound to the device that created it. Multiple keys can be registered, and FIPS-certified devices may suit environments with higher assurance or regulatory requirements. | Administrators needing device-bound credentials or a hardware-controlled assurance model. |
| Other supported MFA methods | Can be easier to deploy, but one-time codes can be socially engineered if a user is tricked into reading or entering the code. | Situations where passkeys or keys are not yet practical, with additional anti-phishing training and controls. |
A physical key is optional: AWS supports passkeys and other MFA choices as well. AWS reported in 2025 that up to eight MFA devices can be registered for a root or IAM user. Register more than one device where policy permits so loss of a single device does not lock out the account.
Does AWS require MFA for member accounts?
Member-account root users are within the current all-account requirement. Organizations can also reduce the number of member-account root credentials they maintain by using AWS centralized root access management.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
What centralized root access management does
- It can remove unnecessary member-account root passwords and long-term access keys.
- It lets authorized administrators perform certain privileged root tasks centrally, including recovery of S3 buckets or SQS queues protected by deny-all policies.
- It reduces the number of root credentials and MFA devices that the organization must inventory and protect.
Operational decisions after enabling it
- Review every member account’s documented root-use procedure.
- Determine whether a member account still needs long-lived root sign-in.
- If it does not, delete that account’s root login profile to remove the password-based credential path and avoid routine root-password and MFA-device maintenance.
- Keep the Organizations management-account root user separate in your protection plan; centralized member-account controls do not eliminate that identity.
Implementation checklist for AWS administrators
- Inventory standalone, management and member accounts and identify which root users already have MFA.
- Read the sign-in notices for each account to determine its staged enforcement timing.
- Choose a phishing-resistant passkey or security key when your recovery and assurance requirements support it.
- Register multiple approved MFA devices, up to AWS’s stated limit of eight per root user.
- Store recovery procedures securely and test that an authorized administrator can use them without weakening separation of duties.
- For Organizations, evaluate centralized root access management before maintaining separate member-account root passwords and keys.
- After centralization, remove obsolete member-account root login profiles and update runbooks.
- Keep an emergency process for the management-account root user and review it whenever AWS changes its IAM guidance.
What happened to AWS’s free security-key offer?
AWS’s free MFA security-key programme ended on 6 November 2025. AWS no longer accepts new orders through that programme, although devices already issued continue to work. Organizations choosing hardware keys must therefore use their normal procurement route; buying a key is not mandatory because passkeys remain supported.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Frequently Asked Questions
Can I use a passkey for AWS MFA?
Yes. AWS supports FIDO2 passkeys for root and IAM users and recommends passkeys or security keys where possible because they provide phishing-resistant authentication.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
- FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
- Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
- Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
- Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
- FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
Does every account get the same AWS MFA enforcement date?
No. AWS described a gradual rollout with advance notifications. Check the notices and guidance for each standalone, management or member account.
The Bottom Line
AWS’s root-user MFA policy now covers every account type. Configure a phishing-resistant passkey or security key, register backup devices, and use centralized root access management to reduce member-account credential exposure where it fits your organization.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

