How to Remove Root User Credentials Across an AWS Organization
Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.
AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your organization.
Prerequisites
- AWS Organizations with all features enabled.
- IAM and Organizations permissions in the management account.
- An understanding of which tasks still need root (rare in member accounts).
Step 1: Enable trusted access
In the IAM console of the management account, open Root access management and enable:
- Root credentials management — to view and delete root credentials in member accounts.
- Privileged root actions in member accounts — to perform specific root-only tasks centrally.
Optionally, register a delegated administrator (for example, your security account) to perform these tasks.
Step 2: Review current root credentials
The console shows which member accounts have root passwords, access keys, MFA devices or signing certificates.
Step 3: Delete root credentials
Delete root passwords, access keys and MFA devices for member accounts. New accounts created in the organization can start without root credentials.
Step 4: Use privileged root actions when needed
For tasks like unlocking a misconfigured bucket policy, use the centralized privileged action (which issues a short-lived, task-scoped session) instead of signing in as root.
Step 5: Protect the management account root
Centralized management doesn't apply to the management account itself. Protect it with a strong password, hardware MFA (multiple devices registered), no access keys and restricted knowledge of credentials.
Step 6: Add guard rails
- SCP denying actions by the root user in member accounts (except where needed).
- Alerts on any root sign-in or root activity.
Verify
IAM credential reports show no root credentials in member accounts.
- AWS Centralized Root Access Management (Nov 2024): Removing Root Credentials From Member Accounts Platform Changes
- AWS Root User Lockdown Checklist How-To & Hardening
- CIO Brief: The Most Powerful AWS Credential — and How to Retire It CIO Briefings