logo

AWS is pushing ahead with MFA for privileged accounts. What that means for you ...

ID: 17546e4d-56a5-5452-a64c-873da0805c30

STIX ID: report--17546e4d-56a5-5452-a64c-873da0805c30

Feed Name: The Register (Security)

Date Published: 2024-06-17

Date Updated: 2026-04-26

Author: Jessica Lyons and Chris Williams

...
...

AWS is mandating multi-factor authentication for root users—initially within AWS Organizations and from July for standalone accounts—with a 30-day grace period, and is adding support for FIDO2 passkeys to make strong authentication easier across devices. Framed by rising credential-based attacks and the Snowflake-related breaches, AWS positions MFA as a critical control to mitigate credential stuffing, spraying, and brute-force attempts while improving usability through passkeys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.