Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Secure a New AWS Account: Root MFA, No Root Keys, an Admin IAM User with MFA, a CloudTrail Trail and a Zero-Spend Budget

Beginner40 minYour own AWS account (free tier) · Authenticator app (Google Authenticator or Microsoft Authenticator) · Browser

Course: Cyber Security · Chapter 30: Cloud and AWS Security

Chapter 30 covers cloud and AWS security; this lab applies the first-day checklist every AWS account should get.

Chala mitrano! The AWS root user is like the master key of a building: it can do everything, including closing the account. So we lock it in a safe with MFA, and do daily work with a separate admin user. Then we switch on the CCTV (CloudTrail) and a money alarm (budget). First-day checklist, 40 minutes. Chala!

Suppose we are…

Suppose we have just joined Zepto as a cloud engineer, and a new AWS account was opened for a hackathon team. Before anyone launches anything, the security lead hands us a first-day checklist: root MFA, no root access keys, an admin IAM user with MFA for daily work, an activity log (CloudTrail) and a billing alarm. We practise it on our own AWS account.

Goal of this lab

By the end you will have:

  • MFA on the root user and proof that root has no access keys.
  • An IAM user admin-<yourname> with AdministratorAccess and its own MFA.
  • A CloudTrail trail recording management events, a zero-spend budget, and green ticks in IAM's security recommendations.

What you need (all free)

  • Your own AWS account (Lab 4) and the root email and password.
  • An authenticator app on your phone. About 40 minutes.
  • Cost: ₹0. One CloudTrail trail of management events is free; its S3 logs are tiny. Do not enable KMS encryption on the trail (step 11), because a KMS key costs about $1 per month.

Safety and ethics

Secure only accounts you own or administer. Never share the root password or MFA codes, and never paste access keys into code, chats or screenshots.

Part 1: lock the root user

  1. Sign in at https://console.aws.amazon.com as Root user with your email and password.
  2. Click your account name (top right) → Security credentials. Under Multi-factor authentication (MFA) click Assign MFA device.
  3. Device name root-phone, choose Authenticator app → Next. Scan the QR code with your phone, type two consecutive codes → Add MFA.

    What you should see: your device listed under MFA with type Virtual.

  4. On the same page scroll to Access keys.

    What you should see: no access keys. If one exists, click Actions → Deactivate, then Delete. The root user should never have keys.

Part 2: an admin user for daily work

  1. Open IAM → Users → Create user. User name admin-yourname, tick Provide user access to the AWS Management Console, choose I want to create an IAM user, set a custom password from your password manager → Next.
  2. Choose Attach policies directly, tick AdministratorAccess → Next → Create user. Copy the Console sign-in URL shown.
  3. Open IAM → Dashboard. Under AWS Account copy the Sign-in URL for IAM users, and save it in your password manager with the new user.
  4. Sign out of root. Open the sign-in URL and log in as admin-yourname.
  5. Add MFA for this user too: IAM → Users → admin-yourname → Security credentials → Assign MFA device → same steps as step 3, name admin-phone.

    What you should see: at the top right, admin-yourname @ 1234-5678-9012, not your root email.

Part 3: activity log and money alarm

  1. Open CloudTrail → Event history. AWS already keeps 90 days of management events here for free. Filter Event name = ConsoleLogin.

    What you should see: your sign-ins from steps 1 and 8, with time, user and source IP.

  2. Create a trail so events are kept longer: CloudTrail → Trails → Create trail. Name account-trail, Create new S3 bucket (keep the suggested name), untick Log file SSE-KMS encryption, keep Log file validation enabled → Next → Management events, Read and Write → Next → Create trail.

  3. Open Billing and Cost Management → Budgets → Create budget → Use a template → Zero spend budget. Enter your email → Create budget. (If you made one in Lab 4, just confirm it exists.)
  4. Open IAM → Dashboard → Security recommendations.

    What you should see: green ticks for Root user has MFA and Root user has no active access keys.

  5. From now on use only admin-yourname. Write down which few tasks still need root (for example changing the account's support plan or closing the account), and keep the root password and MFA in a safe place.

Ravindra Bagale's Tip

Big companies go one step further and use IAM Identity Center for people and roles for apps, with no long-lived keys at all. For your learning account, an admin IAM user with MFA is a good start. The rule stays the same: root locked away, daily work with less power. Root la haat lavu naka!

Common mistakes

Mistake What happens Fix
Doing daily work as root One stolen password can delete everything Use the admin IAM user; root only for rare tasks
Creating root access keys "for the CLI" Keys with unlimited power can leak Never create root keys; use an IAM user or role
Leaving SSE-KMS ticked on the trail A KMS key costs about $1 per month Untick it, or schedule the key for deletion
Losing the MFA phone without a backup Account recovery is slow Save backup codes or add a second MFA device
Ignoring budget emails Charges grow unnoticed Act on the first alert (Lab 4 clean-up)

Self-check checklist

0 of 6 done

Try-at-home challenge

In CloudTrail Event history, find the event that created your IAM user and the one that attached AdministratorAccess. Which user performed them and from which IP?

Check your answer

Filter Event name = CreateUser and then AttachUserPolicy. Open each event: User name shows root (you created the user while signed in as root), and Source IP address shows your home or office public IP (Lab 1). This is exactly how investigators trace who changed what.

Clean up to avoid charges

  1. Keep root MFA, the admin user, its MFA and the zero-spend budget: they are free and keep you safe.
  2. The trail is free for management events, and its S3 logs cost almost nothing. If you want zero storage: CloudTrail → Trails → account-trail → Delete, then S3 → the aws-cloudtrail-logs-… bucket → Empty → Delete. Event history (90 days) stays.
  3. If you accidentally created a KMS key: KMS → Customer managed keys → select it → Key actions → Schedule key deletion → 7 days.
  4. Next month open Billing and Cost Management → Bills and confirm ₹0.

Samjla ka? Root locked, admin with MFA, CCTV on, money alarm set. Aata pudhe jaauya: Chapter 31 reads logs like a SOC analyst.