| name | cis-aws-foundations-2.5 |
| description | Ensure MFA is enabled for the 'root' user account |
| category | cis-iam |
| version | 7.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","iam","root","mfa","authentication"] |
| cis_id | 2.5 |
| cis_benchmark | CIS AWS Foundations Benchmark v7.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-foundations-2.4","cis-aws-foundations-2.6","cis-aws-foundations-2.7","cis-aws-foundations-2.10"] |
| prerequisites | [] |
| severity_boost | {} |
Ensure MFA is enabled for the 'root' user account
Description
The 'root' user account is the most privileged user in an AWS account. Multi-Factor Authentication (MFA) adds an extra layer of protection on top of a username and password. With MFA enabled, when a user signs in to an AWS website, they are prompted for their username and password as well as an authentication code from their MFA device.
Note: When virtual MFA is used for 'root' accounts, it is recommended that the device used is not a personal device, but rather a dedicated mobile device (tablet or phone) that is kept charged and secured, independent of any individual ("non-personal virtual MFA"). This reduces the risk of losing access to MFA due to device loss, device replacement, or employee turnover.
Where an AWS Organization is using centralized root access, root credentials can be removed from member accounts. In that case, it is neither possible nor necessary to configure root MFA in the member account.
Rationale
Enabling MFA increases security for console access by requiring the authenticating principal to possess a device that generates a time-sensitive authentication code, in addition to their credentials.
Impact
Without MFA, the root account is highly susceptible to compromise, potentially resulting in full account takeover and unrestricted access to all resources.
Audit Procedure
Using AWS Console
- Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam.
- Click on
Credential Report.
- Download the
.csv file containing credential usage for all IAM users within an AWS Account.
- Open this file.
- For the
root user, ensure:
mfa_active is set to TRUE, or
password_enabled is set to FALSE
Using AWS CLI
- Run the following command:
aws iam get-account-summary | grep "AccountMFAEnabled"
aws iam get-account-summary | grep "AccountPasswordPresent"
- Ensure:
AccountMFAEnabled property is set to 1, or
AccountPasswordPresent property is set to 0
Expected Result
AccountMFAEnabled is set to (MFA enabled) or is set to (console access removed).