How to validate the Trusted Advisor MFA on Root Account List?

0

Hi Team, One of my customer has 90 sub-accounts which are not root accounts but is being highlighted in the Trusted Advisor MFA on Root not enabled report. How do we verify or validate these sub-accounts which don't really need an MFA and they are all tied up to a single payerid which has MFA enabled.

AWS
已提问 6 个月前244 查看次数
1 回答
0

Every AWS account has a root user. This will be why it’s being reported. True when you create an account in an org there is no password but an email address is required. The way to log into the account is to perform a password recovery.

Usual to satisfy the AWS control each account would require an MFA device adding to root.

Aws CONFIG and backed with security hub will also provide the same insight if configured across the org.

profile picture
专家
已回答 6 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则