How to Create an IAM User with MFA Instead of Using the Root User
To stop using the AWS root user, first add MFA to root (account menu → Security credentials → Assign MFA device), then go to IAM → Users → Create user, give console access with a password, and add the user to a group that has only the permissions it needs. Sign in with the account sign-in URL https://ACCOUNT_ID.signin.aws.amazon.com/console, change the password, and assign an MFA device to the new user too. Use root only for the few tasks that really need it.
Come on, friends! You log in with the email you used to create the AWS account – that is the root user. Root is the master key of the house: it opens everything, it can even close the account. Do you carry the master key in your pocket every day? No, right? Today we create a separate IAM user for daily use, and put MFA on both. Even if the password is stolen, nobody gets in without the code on your mobile.
चला मित्रांनो! तुम्ही AWS अकाउंट ज्या ईमेलने बनवलं त्याने लॉगिन करता – तो root user आहे. Root म्हणजे घराची मास्टर की: सगळं उघडते, अकाउंट बंद पण करता येतं. मास्टर की रोज खिशात घेऊन फिरता का? नाही ना. आज आपण रोज वापरायला एक वेगळा IAM यूजर बनवूया, आणि दोघांना MFA लावूया. पासवर्ड चोरला गेला तरी मोबाइलच्या कोड शिवाय कोणी आत येणार नाही.
चलो दोस्तों! आपने AWS अकाउंट जिस ईमेल से बनाया उससे लॉगिन करते हो – वह root user है. Root मतलब घर की मास्टर की: सब खोलती है, अकाउंट बंद भी कर सकती है. मास्टर की रोज़ जेब में लेकर घूमते हो क्या? नहीं ना. आज हम रोज़ इस्तेमाल के लिए एक अलग IAM यूज़र बनाएँगे, और दोनों पर MFA लगाएँगे. पासवर्ड चोरी हो गया तब भी मोबाइल के कोड के बिना कोई अंदर नहीं आएगा.
Quick answer
Two protections, in this order:
Root: account menu (top right) → Security credentials → Assign MFA device → Authenticator app
→ scan QR → enter 2 codes in a row → Add MFA (and delete any root access keys)
IAM: IAM → User groups → Create group "admins" (or a narrower policy)
IAM → Users → Create user → ✔ Provide user access to the AWS Management Console
→ I want to create an IAM user → custom password → Add user to group → Create user
Then: sign in at https://ACCOUNT_ID.signin.aws.amazon.com/console as the IAM user
→ Security credentials → Assign MFA device (same steps as root)
What do I need before creating an IAM user?
- The root user email and password of your AWS account, for the last time in daily work.
- An authenticator app on your phone (Google Authenticator, Microsoft Authenticator, Authy and similar), or a passkey / security key.
- 10 minutes. IAM itself is free.
How does sign-in with MFA work?
The IAM user signs in with a password, then types the 6-digit MFA code from the authenticator app. Only when both are right does AWS open the console. The root user stays locked away with its own MFA.
IAM user आधी पासवर्ड टाकतो, मग authenticator ॲप मधला 6 अंकी MFA कोड टाकतो. दोन्ही बरोबर असतील तेव्हाच AWS कन्सोल उघडतो. Root user स्वतःच्या MFA सोबत बाजूला सुरक्षित ठेवलेला असतो.
IAM user पहले पासवर्ड डालता है, फिर authenticator ऐप का 6 अंकों वाला MFA कोड डालता है. दोनों सही हों तभी AWS कंसोल खोलता है. Root user अपने MFA के साथ अलग सुरक्षित रखा रहता है.
MFA (multi-factor authentication) means two proofs: something you know (the password) and something you have (the phone that generates a new 6-digit code every 30 seconds, or a security key). A stolen password alone is not enough.
How do I create an IAM user with MFA?
Step 1 — Add MFA to the root user
Sign in as root → click your account name (top right) → Security credentials → Multi-factor authentication (MFA) → Assign MFA device. Give the device a name, choose Authenticator app → Next → Show QR code → scan it with the app → type two consecutive codes (wait for the second one) → Add MFA.
On the same page, under Access keys, delete any root access key. The root user should never have access keys.
Step 2 — Create a group with the right permissions
IAM → User groups → Create group → name admins → attach AdministratorAccess → Create user group.
For your own personal learning account, one admin user for yourself is common. For anyone else, and for apps, use narrower policies (for example AmazonS3ReadOnlyAccess) — that is least privilege. Always give permissions to groups, not to individual users.
Step 3 — Create the IAM user
IAM → Users → Create user → user name, for example ravi-admin. Tick Provide user access to the AWS Management Console → choose I want to create an IAM user (the console may suggest IAM Identity Center; that is the choice for companies) → Custom password → tick Users must create a new password at next sign-in if the account is for someone else → Next.
Step 4 — Add the user to the group and create it
Set permissions → Add user to group → tick admins → Next → Create user. The last page shows the Console sign-in URL; download the .csv or copy it.
Ravindra Bagale's Tip
Many students create an IAM user but still sign in with the root email – and then say "the IAM user doesn't work". An IAM user needs the account sign-in URL: https://ACCOUNT_ID.signin.aws.amazon.com/console, or choose IAM user on the sign-in page and enter the 12-digit Account ID. Bookmark this URL. Pay attention: root signs in with an email, IAM with a username – two different things.
Ravindra Bagale's Tip – मराठी
खूप स्टुडंट्स IAM यूजर बनवतात पण लॉगिन करायला पुन्हा root ईमेल वापरतात – आणि मग म्हणतात "IAM यूजर चालत नाही". IAM यूजरला account sign-in URL लागतो: https://ACCOUNT_ID.signin.aws.amazon.com/console, किंवा लॉगिन पेजवर IAM user निवडा आणि 12 अंकी Account ID द्या. हा URL बुकमार्क करा. लक्ष द्या: root चा लॉगिन ईमेल, IAM चा लॉगिन username – दोन वेगळे.
Ravindra Bagale's Tip – हिंदी
बहुत स्टूडेंट्स IAM यूज़र बनाते हैं पर लॉगिन के लिए फिर से root ईमेल इस्तेमाल करते हैं – और फिर कहते हैं "IAM यूज़र नहीं चल रहा". IAM यूज़र को account sign-in URL चाहिए: https://ACCOUNT_ID.signin.aws.amazon.com/console, या लॉगिन पेज पर IAM user चुनो और 12 अंकों का Account ID डालो. यह URL बुकमार्क करो. ध्यान दो: root का लॉगिन ईमेल, IAM का लॉगिन username – दोनों अलग.
Step 5 — Sign in as the IAM user
Sign out of root. Open the sign-in URL, enter the user name and password, and set a new password if asked. From now on, use this user for everyday work. On the IAM dashboard you can create an account alias so the URL becomes https://your-alias.signin.aws.amazon.com/console.
Step 6 — Assign MFA to the IAM user
Signed in as the IAM user → account menu → Security credentials → Assign MFA device → same steps as Step 1. You can register more than one device (for example the phone and a security key) so that losing one phone does not lock you out. 🔐
Optional but common: let IAM users see billing. As root, open Account → IAM user and role access to Billing information → Edit → Activate IAM Access.
Ravindra Bagale's Tip
Don't panic when a code expires while you set up MFA. Enter the first code, wait 30 seconds, and put the next, new code in the second box – the same code twice does not work. And before you change your phone, move MFA to the new phone; otherwise root recovery needs verification by email and phone call – it takes time. Don't forget this!
Ravindra Bagale's Tip – मराठी
MFA लावताना कोड एक्सपायर झाला म्हणून घाबरून जाऊ नका. पहिला कोड टाका, 30 सेकंद थांबा, आणि पुढचा नवीन कोड दुसऱ्या बॉक्स मध्ये टाका – दोन सेम कोड चालत नाहीत. आणि फोन बदलण्याआधी MFA नवीन फोनवर हलवा, नाहीतर root रिकव्हरी साठी ईमेल आणि फोन कॉलने व्हेरिफिकेशन करावं लागतं – वेळ जातो. बिलकुल विसरू नका!
Ravindra Bagale's Tip – हिंदी
MFA लगाते समय कोड एक्सपायर हो गया तो घबराओ मत. पहला कोड डालो, 30 सेकंड रुको, और अगला नया कोड दूसरे बॉक्स में डालो – दो एक जैसे कोड नहीं चलते. और फ़ोन बदलने से पहले MFA नए फ़ोन पर ले जाओ, वरना root रिकवरी के लिए ईमेल और फ़ोन कॉल से वेरिफ़िकेशन करना पड़ता है – समय जाता है. बिल्कुल मत भूलना!
Step 7 — Check the security status
Open the IAM dashboard. The security recommendations should show MFA for the root user and no root access keys. When you need programmatic access for the CLI, create an access key for the IAM user, never for root: How to Install and Configure AWS CLI. On EC2, use an IAM role instead of keys.
How do I fix common IAM sign-in problems?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| "Your authentication information is incorrect" | Signing in with the IAM name on the root page, or wrong account ID | Use the account sign-in URL, or choose IAM user and enter the Account ID |
| MFA setup says the codes are wrong | Same code typed twice, or phone clock is wrong | Enter two consecutive codes; set the phone time to automatic |
| IAM user gets Access denied everywhere | User not in a group, or the group has no policy | Add the user to the group; check the group's permissions |
| IAM admin cannot open Billing | IAM billing access not activated | As root: Account → IAM user and role access to Billing information → Activate |
| Lost the MFA phone (IAM user) | Device gone | Another admin removes the MFA device in IAM → Users → Security credentials |
| Lost the MFA phone (root) | Device gone | Use a second registered MFA device, or the Troubleshoot MFA link on the root sign-in page |
Learn it properly
This guide is the short path. The free Cyber Security course explains IAM security in depth:
Samajla ka? Got it? MFA on root, an IAM user for daily work, permissions through a group, the sign-in URL bookmarked, and MFA on the IAM user too. The master key is locked in the cupboard – your account is much safer now. Next, let's configure the CLI.
समजलं का? Root ला MFA, रोजसाठी IAM यूजर, ग्रुप मधून permissions, sign-in URL बुकमार्क, आणि IAM यूजरला पण MFA. मास्टर की कपाटात ठेवली – आता तुमचं अकाउंट खूप सुरक्षित आहे. आता पुढे जाऊया CLI कॉन्फिगर करायला.
समझ आया? Root पर MFA, रोज़ के लिए IAM यूज़र, ग्रुप से permissions, sign-in URL बुकमार्क, और IAM यूज़र पर भी MFA. मास्टर की अलमारी में रख दी – अब आपका अकाउंट बहुत सुरक्षित है. अब आगे चलते हैं CLI कॉन्फ़िगर करने.
Frequently asked questions
Why should I not use the AWS root user every day?
The root user can do everything, including closing the account and changing billing, and its permissions cannot be limited. If its password leaks, the whole account is lost. Use it only for the few tasks that need root.
How do I add MFA to an IAM user?
Sign in as the user, open Security credentials from the account menu, choose Assign MFA device, pick an authenticator app, passkey or security key, and for an app scan the QR code and enter two consecutive codes.
Which permissions should my IAM user get?
Only what the work needs (least privilege). For your own learning account an admin group is common, but for other people and apps attach narrow policies, and put users in groups instead of attaching policies to each user.
What is the IAM user sign-in URL?
It is https://ACCOUNT_ID.signin.aws.amazon.com/console, shown on the IAM dashboard. You can create an account alias to replace the number with a name.
Why can my IAM admin user not see the Billing pages?
By default only root sees billing. As root, open Account, find IAM user and role access to Billing information, and activate it.
Should I use IAM users or IAM Identity Center?
AWS recommends IAM Identity Center for people in organisations, because it gives short-lived credentials. An IAM user with MFA is still the simplest safe start for a personal learning account.