AWSHow-To & HardeningRetrospectives

AWS Root User Lockdown Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.

Use this checklist to lock down the AWS root user across your organization.

Management account

  • Root password strong and stored securely (with documented access procedure).
  • Multiple MFA devices registered (preferably FIDO2 hardware keys) and stored separately.
  • No root access keys.
  • Contact information and security contacts current.
  • Root used only for tasks that require it, with documented approvals.

Member accounts

  • Centralized root access management enabled.
  • Root credentials (password, access keys, MFA, certificates) deleted.
  • New accounts created without root credentials.
  • Privileged root actions performed centrally only.

Guard rails

  • SCP restricting root user actions in member accounts.
  • AWS Config or Security Hub controls for root MFA and access keys monitored (for the management account and any exceptions).

Monitoring

  • Alerts on ConsoleLogin by root.
  • Alerts on any API call where userIdentity.type is Root.
  • Alerts on centralized root actions (AssumeRoot).

Process

  • Documented procedure for root-only tasks.
  • Break-glass access to the management account root tested annually.
  • Review of root-related findings quarterly.

Example detection

AWSCloudTrail
| where UserIdentityType == "Root"
| project TimeGenerated, RecipientAccountId, EventName, SourceIpAddress, UserAgent

Any result outside a planned task should be investigated.

aws root user lockdown checklistCentralized root access2024

More on this story