AWS Root User Lockdown Checklist
Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.
Use this checklist to lock down the AWS root user across your organization.
Management account
- Root password strong and stored securely (with documented access procedure).
- Multiple MFA devices registered (preferably FIDO2 hardware keys) and stored separately.
- No root access keys.
- Contact information and security contacts current.
- Root used only for tasks that require it, with documented approvals.
Member accounts
- Centralized root access management enabled.
- Root credentials (password, access keys, MFA, certificates) deleted.
- New accounts created without root credentials.
- Privileged root actions performed centrally only.
Guard rails
- SCP restricting root user actions in member accounts.
- AWS Config or Security Hub controls for root MFA and access keys monitored (for the management account and any exceptions).
Monitoring
- Alerts on
ConsoleLoginby root. - Alerts on any API call where
userIdentity.typeisRoot. - Alerts on centralized root actions (
AssumeRoot).
Process
- Documented procedure for root-only tasks.
- Break-glass access to the management account root tested annually.
- Review of root-related findings quarterly.
Example detection
AWSCloudTrail
| where UserIdentityType == "Root"
| project TimeGenerated, RecipientAccountId, EventName, SourceIpAddress, UserAgent
Any result outside a planned task should be investigated.