← All stories
● Covered by 1 source · 1 reportMedium impact1 positive

AWS enforces MFA for all root users across all account types by June 2025

🔄 Updated 12h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • AWS enforced MFA for all root users across all account types by June 2025.
  • The rollout began in May 2024 with management account root users.
  • MFA prevents over 99% of password-related attacks.
  • AWS supports FIDO2 passkeys and FIDO-certified security keys for MFA.

AWS Completes MFA Enforcement

AWS has completed a comprehensive enforcement of multi-factor authentication (MFA) for root users across all account types by June 2025. This initiative marks a significant milestone, making AWS the first major cloud provider to achieve this level of MFA enforcement.

The enforcement was a deliberate, phased security journey. It began in May 2024 by requiring MFA for AWS Organizations management account root users, expanded to standalone account root users in June 2024, introduced centralized root access management in November 2024, and concluded with member accounts.

Supporting ASD's MFA Campaign

This AWS action supports the Australian Signals Directorate's (ASD) "Multi-factor authentication: Switch it on" campaign. The campaign urges businesses, organizations, and individuals to enable MFA across their online accounts to counter threats like phishing, credential stuffing, and social engineering.

MFA is recognized as one of the most effective security controls available and is a cornerstone of ASD’s Essential Eight maturity model and other major cybersecurity frameworks.

Impact and Availability

MFA prevents over 99% of password-related attacks, significantly enhancing online security. AWS provides MFA to all customers at no additional cost, supporting FIDO2 passkeys and FIDO-certified security keys for phishing-resistant authentication.

This enforcement reflects AWS's commitment to secure-by-design principles, setting a high default security posture for customers and demonstrating that MFA can be a standard practice for organizations of any scale.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

AWS completed comprehensive multi-factor authentication (MFA) enforcement for root users across all account types by June 2025, a phased rollout that began in May 2024. This move supports the Australian Signals Directorate's (ASD) campaign to encourage MFA adoption, aiming to prevent over 99% of password-related attacks.