The root user of an AWS account can do anything in it — change billing, delete every resource, close the account — and whoever has its password can run resources billed to you. AWS now requires MFA for the root user of every account type, and IAM users can be protected the same way. An authenticator app is the method that needs no extra hardware.
Assign a virtual MFA device in AWS
AWS asks for two consecutive codes, not one: type the code the extension shows into “MFA code 1”, wait until it changes — up to 30 seconds — and type the new one into “MFA code 2”. Then choose “Add MFA” right away; AWS warns that waiting too long leaves the device out of sync. For an IAM user, the same wizard is in the IAM console under Users → the user’s name → “Security credentials” tab → “Assign MFA device”.
- Sign in to the AWS Management Console on your computer as the root user — choose “Root user” and enter the account’s email address and password.
- On the right side of the navigation bar, choose your account name, then “Security credentials”.
- In the “Multi-Factor Authentication (MFA)” section, choose “Assign MFA device”.
- Type a “Device name” you will recognize, choose “Authenticator app”, then “Next”.
- Choose “Show QR code”, leave it on the screen and add it to the extension as described below — then enter two consecutive codes from the extension into “MFA code 1” and “MFA code 2” and choose “Add MFA”.
Add AWS to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the AWS page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to AWS and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- AWS confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on AWS’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeAWS has no backup codes — plan a second way in
AWS does not hand out backup codes. Instead it suggests a secure copy of the QR code or secret key, or more than one MFA device — the root user and each IAM user can register up to eight. The simplest: while the QR code is on the screen, scan it with an authenticator app on your phone as well, or add a passkey or security key afterwards. If every device is lost, the root user can still sign in by verifying the account’s email address and primary contact phone number, so keep both current; an IAM user has to ask an administrator to remove the device.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use a browser authenticator as an AWS virtual MFA device?
- Yes. AWS accepts any app that follows RFC 6238, the standard for time-based six-digit codes, and does not check what device runs it. The Authenticator extension reads the QR code straight off the console. AWS does rate passkeys and security keys as stronger against phishing, so consider adding one as a second device.
- What if I lose access to my authenticator?
- Sign in with another MFA device if you registered one. Otherwise, as the root user choose “Troubleshoot MFA” at the MFA prompt, then “Sign in using alternative factors”: AWS sends a verification email to the account address and calls the primary contact phone number. If neither is reachable, AWS Support has to remove the device. IAM users ask their administrator to deactivate it.
- Why does AWS say my MFA code is wrong?
- Check the computer clock first: a clock a minute off produces codes AWS refuses. If the clock is right, the device may be out of sync — usually because the two setup codes were entered too slowly. Resync it under Security credentials: select the device, choose “Resync” and enter two consecutive codes. The troubleshooting link on the sign-in page offers the same.
- Why does AWS ask for two MFA codes?
- It is how AWS confirms a new virtual MFA device, and the same two-code step is used to resync one later. Enter the current code in “MFA code 1”, wait for the code in the extension to change, and enter the new one in “MFA code 2” — not the same code twice. Then submit straight away.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free