Labs · Cyber Security
Lab: Secure a New AWS Account: Root MFA, No Root Keys, an Admin IAM User with MFA, a CloudTrail Trail and a Zero-Spend Budget
Course: Cyber Security · Chapter 30: Cloud and AWS Security
Chapter 30 covers cloud and AWS security; this lab applies the first-day checklist every AWS account should get.
Chala mitrano! The AWS root user is like the master key of a building: it can do everything, including closing the account. So we lock it in a safe with MFA, and do daily work with a separate admin user. Then we switch on the CCTV (CloudTrail) and a money alarm (budget). First-day checklist, 40 minutes. Chala!
चला मित्रांनो! AWS root user म्हणजे इमारतीची master key: ती सगळं करू शकते, account बंद करणं सुद्धा. म्हणून आपण तिला MFA सोबत तिजोरीत ठेवणार, आणि रोजचं काम वेगळ्या admin user ने करणार. मग CCTV (CloudTrail) आणि पैशाचा alarm (budget) चालू करणार. पहिल्या दिवसाची checklist, 40 मिनिटं. चला!
चलो दोस्तों! AWS root user एक building की master key जैसा है: वो सब कुछ कर सकता है, account बंद करना भी। इसलिए हम उसे MFA के साथ तिजोरी में रखेंगे, और रोज़ का काम अलग admin user से करेंगे। फिर CCTV (CloudTrail) और पैसों का alarm (budget) चालू करेंगे। पहले दिन की checklist, 40 मिनट। चलो!
Suppose we are…
Suppose we have just joined Zepto as a cloud engineer, and a new AWS account was opened for a hackathon team. Before anyone launches anything, the security lead hands us a first-day checklist: root MFA, no root access keys, an admin IAM user with MFA for daily work, an activity log (CloudTrail) and a billing alarm. We practise it on our own AWS account.
Goal of this lab
By the end you will have:
- MFA on the root user and proof that root has no access keys.
- An IAM user
admin-<yourname>with AdministratorAccess and its own MFA. - A CloudTrail trail recording management events, a zero-spend budget, and green ticks in IAM's security recommendations.
What you need (all free)
- Your own AWS account (Lab 4) and the root email and password.
- An authenticator app on your phone. About 40 minutes.
- Cost: ₹0. One CloudTrail trail of management events is free; its S3 logs are tiny. Do not enable KMS encryption on the trail (step 11), because a KMS key costs about $1 per month.
Safety and ethics
Secure only accounts you own or administer. Never share the root password or MFA codes, and never paste access keys into code, chats or screenshots.
Part 1: lock the root user
- Sign in at
https://console.aws.amazon.comas Root user with your email and password. - Click your account name (top right) → Security credentials. Under Multi-factor authentication (MFA) click Assign MFA device.
-
Device name
root-phone, choose Authenticator app → Next. Scan the QR code with your phone, type two consecutive codes → Add MFA.What you should see: your device listed under MFA with type Virtual.
-
On the same page scroll to Access keys.
What you should see: no access keys. If one exists, click Actions → Deactivate, then Delete. The root user should never have keys.
Part 2: an admin user for daily work
- Open IAM → Users → Create user. User name
admin-yourname, tick Provide user access to the AWS Management Console, choose I want to create an IAM user, set a custom password from your password manager → Next. - Choose Attach policies directly, tick AdministratorAccess → Next → Create user. Copy the Console sign-in URL shown.
- Open IAM → Dashboard. Under AWS Account copy the Sign-in URL for IAM users, and save it in your password manager with the new user.
- Sign out of root. Open the sign-in URL and log in as
admin-yourname. -
Add MFA for this user too: IAM → Users → admin-yourname → Security credentials → Assign MFA device → same steps as step 3, name
admin-phone.What you should see: at the top right,
admin-yourname @ 1234-5678-9012, not your root email.
Part 3: activity log and money alarm
-
Open CloudTrail → Event history. AWS already keeps 90 days of management events here for free. Filter Event name =
ConsoleLogin.What you should see: your sign-ins from steps 1 and 8, with time, user and source IP.
-
Create a trail so events are kept longer: CloudTrail → Trails → Create trail. Name
account-trail, Create new S3 bucket (keep the suggested name), untick Log file SSE-KMS encryption, keep Log file validation enabled → Next → Management events, Read and Write → Next → Create trail. - Open Billing and Cost Management → Budgets → Create budget → Use a template → Zero spend budget. Enter your email → Create budget. (If you made one in Lab 4, just confirm it exists.)
-
Open IAM → Dashboard → Security recommendations.
What you should see: green ticks for Root user has MFA and Root user has no active access keys.
-
From now on use only
admin-yourname. Write down which few tasks still need root (for example changing the account's support plan or closing the account), and keep the root password and MFA in a safe place.
Ravindra Bagale's Tip
Big companies go one step further and use IAM Identity Center for people and roles for apps, with no long-lived keys at all. For your learning account, an admin IAM user with MFA is a good start. The rule stays the same: root locked away, daily work with less power. Root la haat lavu naka!
Ravindra Bagale's Tip – मराठी
मोठ्या companies एक पाऊल पुढे जातात आणि लोकांसाठी IAM Identity Center आणि apps साठी roles वापरतात, कुठलीही long-lived keys नाहीत. तुमच्या learning account साठी MFA सह admin IAM user ही चांगली सुरुवात आहे. नियम तोच: root बंद करून ठेवा, रोजचं काम कमी power ने. Root ला हात लावू नका!
Ravindra Bagale's Tip – हिंदी
बड़ी companies एक कदम आगे जाती हैं और लोगों के लिए IAM Identity Center और apps के लिए roles इस्तेमाल करती हैं, कोई long-lived keys नहीं। आपके learning account के लिए MFA वाला admin IAM user अच्छी शुरुआत है। नियम वही: root बंद रखो, रोज़ का काम कम power से। Root को हाथ मत लगाओ!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Doing daily work as root | One stolen password can delete everything | Use the admin IAM user; root only for rare tasks |
| Creating root access keys "for the CLI" | Keys with unlimited power can leak | Never create root keys; use an IAM user or role |
| Leaving SSE-KMS ticked on the trail | A KMS key costs about $1 per month | Untick it, or schedule the key for deletion |
| Losing the MFA phone without a backup | Account recovery is slow | Save backup codes or add a second MFA device |
| Ignoring budget emails | Charges grow unnoticed | Act on the first alert (Lab 4 clean-up) |
Self-check checklist
0 of 6 done
Try-at-home challenge
In CloudTrail Event history, find the event that created your IAM user and the one that attached AdministratorAccess. Which user performed them and from which IP?
Check your answer
Filter Event name = CreateUser and then AttachUserPolicy. Open each event: User name shows root (you created the user while signed in as root), and Source IP address shows your home or office public IP (Lab 1). This is exactly how investigators trace who changed what.
Clean up to avoid charges
- Keep root MFA, the admin user, its MFA and the zero-spend budget: they are free and keep you safe.
- The trail is free for management events, and its S3 logs cost almost nothing. If you want zero storage: CloudTrail → Trails → account-trail → Delete, then S3 → the
aws-cloudtrail-logs-…bucket → Empty → Delete. Event history (90 days) stays. - If you accidentally created a KMS key: KMS → Customer managed keys → select it → Key actions → Schedule key deletion → 7 days.
- Next month open Billing and Cost Management → Bills and confirm ₹0.
Samjla ka? Root locked, admin with MFA, CCTV on, money alarm set. Aata pudhe jaauya: Chapter 31 reads logs like a SOC analyst.