Root and IAM Users

Root, IAM Users and Why You Never Use Root

The email and password you sign up with belong to the root user, which can do anything, including closing the account and changing payment details, and which no policy can restrict. AWS 24 enforces MFA on root and tells you to keep it for the few tasks only root can do. Check which identity you are using; an ARN ending in :root is the warning sign:

Asking AWS which identity the CLI is usingShell
aws sts get-caller-identity --query Arn --output text
Output
arn:aws:iam::123456789012:root

For daily work, create another identity. An IAM user has a password and, optionally, access keys that never expire, which is how keys end up in Git 1,932 repositories. AWS recommends IAM Identity Center instead (no extra charge): you sign in through a portal with MFA and receive temporary credentials for a permission set such as AdministratorAccess. As root, enable Identity Center, create your user and a permission set, assign both to the account, then sign out of root for good. The CLI side is shown without output, since changing who can sign in was out of bounds for the account used here:

Pointing the CLI at IAM Identity CenterShell
aws configure sso               # portal URL, Region, account, role; writes ~/.aws/config
aws sso login --profile admin   # daily: browser sign-in with MFA, credentials last hours

On servers the rule is the same: never copy keys onto an EC2 24 instance. Attach an IAM role, and the SDKs fetch rotating credentials from the instance metadata service.