Assigning a hardware MFA to my organisation root account.

0

I am planning to assign a hardware MFA to my organisation root account, what if I loose the hardware MFA? or is there any disadvantage for using hardware MFA? or is there anything I should know?

2 個答案
1

You will find more information about Using multi-factor authentication (MFA) in AWS here. And you can read more about What if an MFA device is lost or stops working here.

AWS
Vincent
已回答 8 個月前
profile pictureAWS
專家
kentrad
已審閱 8 個月前
1

Hi,

from documentation: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html

Basically, you can register multiple MFS devices to root user to have a backup if one fails or you must be prepared to use the identity verification procedure if you can't have more than 1 device

Recovering a root user MFA device

If your AWS account root user multi-factor authentication (MFA) device is lost, damaged, 
or not working, you can sign in using another MFA device registered to the same AWS 
account root user. If the root user only has one MFA device enabled, you can use alternative 
methods of authentication. This means that if you can't sign in with your MFA device, you 
can sign in by verifying your identity using the email and the primary contact phone number 
registered with your account.

Before you use alternative factors of authentication to sign in as a root user, you must be 
able to access the email and primary contact phone number that are associated with your 
account. If you need to update the primary contact phone number, you can sign in as an IAM 
user with Administrator access instead of the root user. For additional instructions on updating 
the account contact information, see Editing contact information in the AWS Billing User Guide. 
If you do not have access to an email and primary contact phone number, you must contact AWS 
Support.

Best,

Didier

profile pictureAWS
專家
已回答 8 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南