Tasks that require root user credentials
Important
The following AWS Identity and Access Management (IAM) actions
will reach the end of standard support on July 2023:
aws-portal:ModifyAccount
and aws-portal:ViewAccount
.
See the Using fine-grained AWS Billing actions to replace these actions with
fine-grained actions so you have access to AWS Billing, AWS Cost Management, and AWS
accounts consoles.
If you created your AWS account or AWS Organizations Management
account before March 6, 2023, the fine-grained actions will be effective starting
July 2023. We recommend you to add the fine-grained actions, but not remove your
existing permissions with aws-portal
or purchase-orders
prefixes.
If you created your AWS account or AWS Organizations Management account on or after March 6, 2023, the fine-grained actions are effective immediately.
We recommend that you configure an administrative user in AWS IAM Identity Center (successor to AWS Single Sign-On) to perform daily tasks and access AWS resources. However, you can perform the tasks listed below only when you sign in as the root user of an account.
Tasks
-
Change your account settings. This includes the account name, email address, root user password, and root user access keys. Other account settings, such as contact information, payment currency preference, and AWS Regions, don't require root user credentials.
-
Restore IAM user permissions. If the only IAM administrator accidentally revokes their own permissions, you can sign in as the root user to edit policies and restore those permissions.
-
Activate IAM access to the Billing and Cost Management console.
-
View certain tax invoices. An IAM user with the aws-portal:ViewBilling permission can view and download VAT invoices from AWS Europe, but not AWS Inc. or Amazon Internet Services Private Limited (AISPL).
-
Register as a seller in the Reserved Instance Marketplace.
-
Configure an Amazon S3 bucket to enable MFA (multi-factor authentication).
-
Request AWS GovCloud (US) account root user access keys from AWS Support.