Assigning a hardware MFA to my organisation root account.

0

I am planning to assign a hardware MFA to my organisation root account, what if I loose the hardware MFA? or is there any disadvantage for using hardware MFA? or is there anything I should know?

Sid
已提问 8 个月前341 查看次数
2 回答
1

You will find more information about Using multi-factor authentication (MFA) in AWS here. And you can read more about What if an MFA device is lost or stops working here.

AWS
Vincent
已回答 8 个月前
profile pictureAWS
专家
kentrad
已审核 8 个月前
1

Hi,

from documentation: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html

Basically, you can register multiple MFS devices to root user to have a backup if one fails or you must be prepared to use the identity verification procedure if you can't have more than 1 device

Recovering a root user MFA device

If your AWS account root user multi-factor authentication (MFA) device is lost, damaged, 
or not working, you can sign in using another MFA device registered to the same AWS 
account root user. If the root user only has one MFA device enabled, you can use alternative 
methods of authentication. This means that if you can't sign in with your MFA device, you 
can sign in by verifying your identity using the email and the primary contact phone number 
registered with your account.

Before you use alternative factors of authentication to sign in as a root user, you must be 
able to access the email and primary contact phone number that are associated with your 
account. If you need to update the primary contact phone number, you can sign in as an IAM 
user with Administrator access instead of the root user. For additional instructions on updating 
the account contact information, see Editing contact information in the AWS Billing User Guide. 
If you do not have access to an email and primary contact phone number, you must contact AWS 
Support.

Best,

Didier

profile pictureAWS
专家
已回答 8 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则