AWSCIO BriefingsRetrospectives

CIO Brief: The Most Powerful AWS Credential — and How to Retire It

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.

The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect. Since late 2024, AWS lets you delete them from most accounts and handle rare root tasks centrally — removing a major target.

Why root credentials are dangerous

Root access can delete everything, change billing, lock out other administrators and bypass many security controls. Each root credential is a high-value target, and they're often poorly tracked: who has the password? Where is the MFA device?

The business impact

  • Fewer high-value targets for attackers.
  • Simpler audits — there's no credential to protect if it doesn't exist.
  • Less operational risk from lost passwords or departed employees who held them.

Questions to ask your team

  • How many AWS accounts do we have, and how many still have root credentials?
  • Who knows the root password for our main (management) account, and where is its MFA device?
  • Have we enabled AWS's centralized root management?
  • Would we be alerted if someone used root?

What good looks like

Root credentials removed from all member accounts, the management account's root locked down with hardware MFA and controlled access, and alerts on any root activity.

The decision

Ask your cloud team to enable centralized root access management and remove member account root credentials this quarter. It's a short project that eliminates a long-standing risk.

aws centralized root access management impactCentralized root access2024

More on this story