AWSHow-To & HardeningRetrospectives

How to Remove Root User Credentials Across an AWS Organization

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.

AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your organization.

Prerequisites

  • AWS Organizations with all features enabled.
  • IAM and Organizations permissions in the management account.
  • An understanding of which tasks still need root (rare in member accounts).

Step 1: Enable trusted access

In the IAM console of the management account, open Root access management and enable:

  • Root credentials management — to view and delete root credentials in member accounts.
  • Privileged root actions in member accounts — to perform specific root-only tasks centrally.

Optionally, register a delegated administrator (for example, your security account) to perform these tasks.

Step 2: Review current root credentials

The console shows which member accounts have root passwords, access keys, MFA devices or signing certificates.

Step 3: Delete root credentials

Delete root passwords, access keys and MFA devices for member accounts. New accounts created in the organization can start without root credentials.

Step 4: Use privileged root actions when needed

For tasks like unlocking a misconfigured bucket policy, use the centralized privileged action (which issues a short-lived, task-scoped session) instead of signing in as root.

Step 5: Protect the management account root

Centralized management doesn't apply to the management account itself. Protect it with a strong password, hardware MFA (multiple devices registered), no access keys and restricted knowledge of credentials.

Step 6: Add guard rails

  • SCP denying actions by the root user in member accounts (except where needed).
  • Alerts on any root sign-in or root activity.

Verify

IAM credential reports show no root credentials in member accounts.

remove aws root credentials organizationCentralized root access2024

More on this story