What it is

Every AWS account has exactly one root user. Not one per team. Not one per department. One per account.

That identity can delete servers, wipe data, close the account, and change billing. AWS's own advice is to lock it away and almost never use it for day-to-day work. Azure's cousin is Global Admin in Entra ID. Different name. Same "please do not leave this on a sticky note" energy.

Here is what often happens instead: it was set up years ago, two people have left, and nobody is sure who still has the password. MFA is "probably on." Recovery is "in someone's email."

Why it matters in the meeting

When Bart asks whether root is protected, he is not checking a checkbox for fun. He is asking whether a single compromised password can take down production, or open a surprise invoice that nobody can stop in time.

MFA on root is the minimum. A plan for who holds recovery, and when root is allowed at all, is the next step. If the answer is a shrug, the meeting is not done.

Real world

Account takeovers almost always start with credentials that should never have been left open. Root with no MFA is the highest-leverage target in the account. Auditors look for it early because the blast radius is total.

Day-to-day work belongs on IAM users or, better, roles. Root is for the day something is so broken that only the master key will do. That day should be rare enough that you remember it.

In plain terms

Root is not a convenience account. It is the last resort key. Treat it like the physical master key to the building, not the badge everyone shares at the front desk.

What to ask

  • Is MFA enabled on the root user right now?
  • Who holds the recovery method, and is that person still with the company?
  • When was the root password last rotated?
  • Are we still using root for any routine tasks that should use an IAM role instead?

You just knew a little more Jack than you did five minutes ago.

All concepts