AWS organizations: Clarify role creation and root user credential behavior for member accounts
Summary
Added a note that automatic role creation applies only to accounts created directly via AWS Organizations, and clarified that some existing member accounts may still have root user credentials that should be centralized.
Security assessment
Documents root user credential and role naming behavior for member accounts, which is identity/access management guidance with security relevance, but not tied to a specific vulnerability.
Evidence
+When you create a new member account in your organization, the account has no root user credentials by default. Member accounts can't sign in to their root user or perform password recovery for their root user unless account recovery is enabled. This applies to member accounts created in AWS Organizations. Some existing member accounts might still have root user credentials; to remove them, centralize root access for those accounts as described in the following paragraph.
Diff
diff --git a/organizations/latest/userguide/orgs_manage_accounts_access.md b/organizations/latest/userguide/orgs_manage_accounts_access.md index 1e2041d70..2f7dccc46 100644 --- a//organizations/latest/userguide/orgs_manage_accounts_access.md +++ b//organizations/latest/userguide/orgs_manage_accounts_access.md @@ -10,0 +11,4 @@ When you create an account in your organization, in addition to the root user, A +###### Note + +This automatic role creation applies to member accounts that you create directly through AWS Organizations. Accounts that are provisioned by other methods, such as AWS Control Tower or Account Factory for Terraform (AFT), might create a role with a different name. Check the documentation for the method that you use to provision accounts to determine the role name. + @@ -25 +29 @@ Using the root user (Not recommended for everyday tasks) -When you create new member account in your organization, the account has no root user credentials by default. Member accounts can't sign in to their root user or perform password recovery for their root user unless account recovery is enabled. +When you create a new member account in your organization, the account has no root user credentials by default. Member accounts can't sign in to their root user or perform password recovery for their root user unless account recovery is enabled. This applies to member accounts created in AWS Organizations. Some existing member accounts might still have root user credentials; to remove them, centralize root access for those accounts as described in the following paragraph.