CIO Brief: The Most Powerful AWS Credential — and How to Retire It
Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.
The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect. Since late 2024, AWS lets you delete them from most accounts and handle rare root tasks centrally — removing a major target.
Why root credentials are dangerous
Root access can delete everything, change billing, lock out other administrators and bypass many security controls. Each root credential is a high-value target, and they're often poorly tracked: who has the password? Where is the MFA device?
The business impact
- Fewer high-value targets for attackers.
- Simpler audits — there's no credential to protect if it doesn't exist.
- Less operational risk from lost passwords or departed employees who held them.
Questions to ask your team
- How many AWS accounts do we have, and how many still have root credentials?
- Who knows the root password for our main (management) account, and where is its MFA device?
- Have we enabled AWS's centralized root management?
- Would we be alerted if someone used root?
What good looks like
Root credentials removed from all member accounts, the management account's root locked down with hardware MFA and controlled access, and alerts on any root activity.
The decision
Ask your cloud team to enable centralized root access management and remove member account root credentials this quarter. It's a short project that eliminates a long-standing risk.
- AWS Centralized Root Access Management (Nov 2024): Removing Root Credentials From Member Accounts Platform Changes
- How to Remove Root User Credentials Across an AWS Organization How-To & Hardening
- AWS Root User Lockdown Checklist How-To & Hardening