Critical
IAM
Hardware MFA should be enabled for the root user
CIS
Description
Checks if Hardware MFA is enabled for the root user.
Remediation
To enable hardware MFA for the root user, follow these steps:
Steps
- Sign in to the AWS Management Console using your root user credentials.
- Navigate to the IAM Dashboard at https://console.aws.amazon.com/iam/.
- In the navigation pane, click on 'Dashboard'.
- Under the 'Security Status' section, find 'Activate MFA on your root account' and click on 'Manage MFA'.
- Select 'A hardware MFA device' and click 'Continue'.
- Follow the instructions to initialize your hardware MFA device. This typically involves entering the serial number of the device and two consecutive MFA codes generated by the device.
- Once the device is initialized, click 'Activate MFA'.
- Ensure that the hardware MFA device is now listed as active for the root user.
Compliance
CIS