Root user logins in AWS should happen maybe once or twice in the life of an account. If you don't have an alert set up, you won't know when it does. Root access bypasses all IAM policies and SCPs. There's no way to restrict what it can do. Anyone who gets in as root owns the account, full stop.
1 likes 1 replies
?