StudyToCert

All certifications / Cloud Practitioner / Lessons

AWS Certified Cloud Practitioner CLF-C02 · Domain 2: Security and Compliance

Protecting the root user: MFA, no access keys, and the tasks that require root credentials

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

When you create an AWS account, you sign in with the email address and password you used to sign up. That identity is the root user, and it has complete, unrestricted access to every resource and setting in the account, including billing and the ability to close the account. Permissions policies cannot limit the root user of a standalone account. Because it is so powerful, protecting it is one of the first things AWS asks you to do, and questions about it appear regularly on the Cloud Practitioner exam.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Cloud Practitioner for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Cloud Practitioner study plan