An AWS Organizations review shows municipal member accounts still use the root user for daily tasks and several roots lack MFA. Which identity-hygiene improvement should be implemented org-wide?
Select an answer to reveal the explanation.
Short Explanation
Root is the nuclear key—great in a sealed box with MFA, awful as the daily coffee-run badge. Push people to Identity Center or roles and lock root behind MFA for emergencies only. That hygiene upgrade pays rent every day.
Full Explanation
Improving identity security posture over time includes eliminating routine root usage, requiring MFA on root, and standardizing workforce access through IAM Identity Center or least-privilege roles with documented break-glass processes. Encouraging daily root use, sharing root passwords, or substituting broad IAM admins while still using root fails professional hygiene. Continuous improvement treats root control as an org-wide baseline across municipal accounts.