The email and password you sign up with belong to the root user, which can do anything, including closing the account and changing payment details, and which no policy can restrict. AWS 24 enforces MFA on root and tells you to keep it for the few tasks only root can do. Check which identity you are using; an ARN ending in :root is the warning sign:
aws sts get-caller-identity --query Arn --output textarn:aws:iam::123456789012:root
For daily work, create another identity. An IAM user has a password and, optionally, access keys that never expire, which is how keys end up in Git 1,932 repositories. AWS recommends IAM Identity Center instead (no extra charge): you sign in through a portal with MFA and receive temporary credentials for a permission set such as AdministratorAccess. As root, enable Identity Center, create your user and a permission set, assign both to the account, then sign out of root for good. The CLI side is shown without output, since changing who can sign in was out of bounds for the account used here:
aws configure sso # portal URL, Region, account, role; writes ~/.aws/config
aws sso login --profile admin # daily: browser sign-in with MFA, credentials last hoursOn servers the rule is the same: never copy keys onto an EC2 24 instance. Attach an IAM role, and the SDKs fetch rotating credentials from the instance metadata service.