If you control the account's email address, reset the root user password from the AWS sign-in page. If the problem is two-factor login, AWS lets you sign in by verifying the email and the primary contact phone number on the account. If neither the email nor the phone is yours, because your developer set the account up with theirs, you must contact AWS Support, and recovery depends on proving the account is yours.
What's the problem
Your app runs on AWS, but you can't get into the account. The password is unknown, the two-factor device is lost, or the account was opened with your developer's email and phone. Meanwhile it keeps running, and billing, possibly on a card you can't see.
Why it happens
- The root user belongs to an email address. Whoever controls the email the account was created with controls the root user.
- Two-factor devices get lost. A phone replaced or a security key misplaced, with no backup set up.
- The developer set it up for you. With their email, their phone and their two-factor device, so everything that proves ownership points at them.
How to fix it
- Try the root user password reset from the AWS sign-in page if you control the account's email.
- For lost two-factor, use the alternative sign-in, which verifies both the account email and the primary contact phone number.
- If the email and phone are your developer's, ask them to sign in and change the root email and contact phone to yours, or to give you administrator access while they do.
- If that's impossible, contact AWS Support. Have invoices, the account ID, and anything else that shows the account is yours.
- Once you're in: set the root email and contact details to addresses your business controls, turn on two-factor login with a backup method, create separate administrator users for day-to-day work, and remove the developer's access.
- Check what's running and what it costs, and rotate any access keys the developer had.
When to call Preventionlabs
Recovering the account is between you and AWS, and only the account owner can do it. Call us when you're back in and the app needs bringing back, or moving somewhere you understand. We deploy into your own hosting account, under your business's details, and at handover every account we set up is in your control and our access is removed.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- Amazon Web Services: Reset a lost or forgotten root user passwordcloud platform docs
If you forget your root user password, you can reset the password from the AWS Management Console.
- Amazon Web Services: Recover an MFA protected identity in IAMcloud platform docs
If you can't sign in with MFA, you can use alternative methods of authentication to sign in by verifying your identity using the email and the primary contact phone number registered with your account.
- Amazon Web Services: Recover an MFA protected identity in IAMcloud platform docs
If you do not have access to an email and primary contact phone number, you must contact AWS Support.
- Amazon Web Services: Recover an MFA protected identity in IAMcloud platform docs
We recommend that you keep the email address and contact phone number linked to your root user up to date for a successful account recovery.