Critical IAM

MFA should be enabled for the root user

CIS

Description

Confirms that virtual MFA is enabled for the root user.


Remediation

To enable Virtual MFA for the root user, follow these steps:

Steps

  1. Sign in to the AWS Management Console using your root user credentials.
  2. Navigate to the IAM dashboard.
  3. In the IAM dashboard, go to the 'Security Status' section.
  4. Under 'Activate MFA on your root account', click on 'Manage MFA'.
  5. Select 'A virtual MFA device' and click 'Next Step'.
  6. Follow the instructions to set up a virtual MFA device.
  7. Once the virtual MFA device is successfully associated with your root account, verify it works.

Compliance

CIS