Glossary

    Root Account

    Identity & Access

    The Root Account (root user) is the identity created when you first set up an AWS account. It has complete, unrestricted access to all AWS services and resources - it cannot be limited by IAM policies or permission boundaries. In the management account, SCPs do not apply to the root user either. However, in member accounts, SCPs do restrict the root user.

    Because of this unlimited power, the root account is the single most critical identity to protect. A compromised root account means total loss of the AWS environment.

    Security Best Practices

    • Enable MFA immediately (hardware FIDO2 key recommended)
    • Do not create access keys for the root user
    • Use root only for tasks that require it (account settings, billing, support plan changes)
    • Create IAM users or use IAM Identity Center for daily operations
    • Since November 2024, AWS centralized root access management lets you remove root credentials from member accounts entirely
    • Set up CloudTrail alerts for any root account activity

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.