Directorate (ASD) launched a Multi-factor authentication: Switch it on campaign asking businesses, organisations, and individuals to enable MFA across online accounts. AWS endorses the campaign and frames MFA as a simple, effective control against credential-focused attacks such as phishing and credential stuffing.
Passwords alone are routinely targeted by attackers through phishing, credential stuffing, and social engineering. AWS cites that MFA prevents over 99 percent of password-related attacks. Because MFA requires an additional authentication factor, attackers who obtain or guess a password still cannot access the account unless they also bypass the second factor.
AWS implemented MFA enforcement for root users across all account types in June 2025. That rollout followed distinct phases:
- May 2024: Required MFA for AWS Organizations management account root users.
- June 2024: Expanded requirement to standalone account root users.
- November 2024: Introduced centralized root access management.
- June 2025: Completed enforcement across member accounts and all account types.
AWS describes this as the first comprehensive enforcement among major cloud providers and frames the milestone as evidence that organizations of any size can make MFA the standard configuration rather than an optional setting.
Available phishing-resistant options
AWS supports FIDO2 passkeys and FIDO-certified security keys for phishing-resistant authentication. Those methods reduce the effectiveness of real-time phishing and relay attacks because they rely on cryptographic attestations rather than shared codes or push approvals.
A compromise of an email or collaboration account can be used to reset credentials for cloud accounts. Source control breaches can expose secrets used to access infrastructure. AWS recommends enabling MFA on email, collaboration tools, source control systems, and any other services that support it. The ASD campaign page is cited as a broader source of guidance for non-AWS services.
AWS enforces MFA automatically for root users, so the immediate priority for teams is to enforce MFA for daily-use identities. AWS suggests configuring MFA for IAM users through the AWS Management Console and points to IAM security best practices for step-by-step actions. For organizations seeking phishing-resistant options, AWS points to documentation on passkeys and security keys in IAM.
- Audit all accounts you control (email, cloud consoles, collaboration, source control). Enable MFA where supported.
- Prioritize phishing-resistant methods (FIDO2 passkeys or FIDO-certified keys) where available.
- For AWS customers, verify root users have MFA enforced, then roll out MFA for IAM users and service accounts.
- Treat account recovery processes as an attack surface: ensure helpdesk and recovery flows require robust verification.
AWS links to its security resources and invites questions via comments or AWS re:Post. The post explicitly supports the ASD campaign and aggregates AWS security references for teams looking to align their configurations with the guidance.