Lunker - Gone Fishing!

blog.lukach.io

Amazon Cloud

GitHub Profile

December 18, 2025

ClickOps #12 - Centralized Root Access Management

by John Lukach

It is crucial to lock down the root account and enable multi-factor authentication (MFA). As the number of accounts in the organization increases, this becomes harder to sustain. Amazon released the Root Access Management feature to simplify the lockdown.

enable root access

enable root access

The theme continues: we want to limit everything we can in the management account by delegating administration to the identity account for the IAM team.

enable root access

enable root access

The number of supported items has not expanded much since the original release.

root access features

tags: aws - lockdown - mfa - root