The Root Account (root user) is the identity created when you first set up an AWS account. It has complete, unrestricted access to all AWS services and resources - it cannot be limited by IAM policies or permission boundaries. In the management account, SCPs do not apply to the root user either. However, in member accounts, SCPs do restrict the root user.
Because of this unlimited power, the root account is the single most critical identity to protect. A compromised root account means total loss of the AWS environment.
A security mechanism requiring two or more forms of verification (password + device/token) before granting access to an AWS account or resource.
An AWS identity with temporary credentials that can be assumed by users, services, or applications to perform actions without long-term access keys.
An organization-wide guardrail that restricts what actions member accounts can perform, regardless of their IAM policies.
Using multiple AWS accounts to isolate workloads, environments, and teams, providing the strongest security boundary available in AWS.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.