AWS IAM now mandates multi-factor authentication (MFA) for root users across all account types, including member accounts. This security enhancement builds on previous MFA requirements introduced throughout 2024, starting with AWS Organizations management accounts. MFA prevents over 99% of password-related attacks and supports various authentication methods including FIDO2 passkeys and security keys. AWS Organizations customers are recommended to centralize root access management through the management account for enhanced security.
Sort: