AWS has completed a comprehensive enforcement of multi-factor authentication (MFA) for root users across all account types by June 2025. This initiative marks a significant milestone, making AWS the first major cloud provider to achieve this level of MFA enforcement.
The enforcement was a deliberate, phased security journey. It began in May 2024 by requiring MFA for AWS Organizations management account root users, expanded to standalone account root users in June 2024, introduced centralized root access management in November 2024, and concluded with member accounts.
This AWS action supports the Australian Signals Directorate's (ASD) "Multi-factor authentication: Switch it on" campaign. The campaign urges businesses, organizations, and individuals to enable MFA across their online accounts to counter threats like phishing, credential stuffing, and social engineering.
MFA is recognized as one of the most effective security controls available and is a cornerstone of ASD’s Essential Eight maturity model and other major cybersecurity frameworks.
MFA prevents over 99% of password-related attacks, significantly enhancing online security. AWS provides MFA to all customers at no additional cost, supporting FIDO2 passkeys and FIDO-certified security keys for phishing-resistant authentication.
This enforcement reflects AWS's commitment to secure-by-design principles, setting a high default security posture for customers and demonstrating that MFA can be a standard practice for organizations of any scale.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
AWS completed comprehensive multi-factor authentication (MFA) enforcement for root users across all account types by June 2025, a phased rollout that began in May 2024. This move supports the Australian Signals Directorate's (ASD) campaign to encourage MFA adoption, aiming to prevent over 99% of password-related attacks.