AWSPlatform ChangesRetrospectives

AWS Centralized Root Access Management (Nov 2024): Removing Root Credentials From Member Accounts

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.

In November 2024, AWS launched centralized root access management for AWS Organizations. It lets security teams remove root user credentials from member accounts and perform the few privileged root tasks centrally, without ever signing in as root in those accounts.

The problem it solved

Every AWS account has a root user with unrestricted access. AWS has long recommended locking it down: strong password, MFA, no access keys, never used for daily work. But in organizations with dozens or hundreds of accounts, that meant managing dozens or hundreds of root passwords and MFA devices — each a potential target, each a credential to secure and audit.

What changed

With centralized root access management:

  • Root credentials can be deleted from member accounts (password, access keys, signing certificates, MFA devices), and new member accounts can be created without root credentials.
  • The management account or a delegated administrator can run privileged root actions in member accounts through short-lived, task-scoped root sessions — for example, unlocking an S3 bucket policy that denies all principals, or deleting an SQS queue policy that locks everyone out.
  • Root credential recovery can be allowed centrally if ever needed.

Why it mattered

Root credentials are among the most powerful and least monitored secrets in AWS environments. Removing them shrinks the attack surface significantly and simplifies compliance — there's nothing to rotate or protect if the credential doesn't exist.

In hindsight

Alongside earlier improvements such as SCPs restricting root actions and MFA requirements for root users, centralized root management turned "secure the root user" into "remove the root user." For organizations using AWS Organizations, it's one of the most valuable low-effort changes available.

aws centralized root access managementCentralized root access2024

More on this story