Authenticator App - Novaz

Amazon Web Services 2FA Setup Guide

aws.amazon.com SupportedChecked against official help · September 25, 2026

Your AWS sign-in controls the servers, data and billing in your account, so a password alone shouldn't be enough. AWS calls the feature multi-factor authentication (MFA) and an authenticator app a "virtual MFA device", and it accepts six-digit codes from apps like Authenticator App - Novaz for the root user and IAM users.

A Amazon Web Services account can hold your files and backups of everything else, so protect it with 2FA. Besides an authenticator app, Amazon Web Services also offers a hardware token and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, Amazon Web Services also supports hardware security keys.

2FA methods Amazon Web Services supports

  • Authenticator app (TOTP)
  • Hardware token
  • Security key (U2F / WebAuthn)

Before you start

  • Root user: the account email address and password, plus access to that email and the account's primary contact phone number for recovery
  • IAM user: the account ID or alias, your user name and password, and permission to manage your own MFA device; otherwise an administrator assigns it and needs your phone to finish
  • Authenticator App - Novaz installed on your iPhone or iPad
  • The AWS Management Console open on a computer, so your phone can scan its QR code

Part 1: Turn on 2FA in Amazon Web Services

  1. 1

    Open Security credentials

    Sign in to the AWS Management Console. On the right side of the navigation bar, choose your account name (or IAM user name), then choose "Security credentials". Administrators can instead pick a user under "Users" in the IAM console and open the "Security credentials" tab.

  2. 2

    Choose Assign MFA device

    In the "Multi-factor authentication (MFA)" section, choose "Assign MFA device".

  3. 3

    Name the device and choose Authenticator app

    Type a "Device name", choose "Authenticator app" and then choose "Next".

  4. 4

    Show the QR code

    Choose "Show QR code", or "Show secret key" if you'd rather type the key. Leave the page open while you pick up your phone.

Part 2: Add Amazon Web Services to Authenticator App - Novaz

  1. 5

    Add AWS in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. If you chose "Show secret key", choose to enter a setup key and type it exactly as AWS shows it. Then tap "Save".

  2. 6

    Watch for two codes in a row

    Authenticator App - Novaz now shows a six-digit code for AWS. You'll need this code and the next one, which appears within 30 seconds.

Part 3: Confirm and finish

  1. 7

    Enter two consecutive codes

    Type the current code into "MFA code 1", wait for the next code, and type it into "MFA code 2". Choose "Add MFA" straight away: codes submitted too late can leave the device out of sync.

  2. 8

    Know when AWS will ask for a code

    At each console sign-in, AWS shows a second page after your password: type the code from Authenticator App - Novaz into the "MFA code" box.

  3. 9

    Save a way to recover your account

    If Amazon Web Services offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Amazon Web Services recovers accounts before you need it.

If something goes wrong

  • AWS rejects your code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time). After several failed tries, AWS prompts you to resynchronize the device.
  • Codes stop working after setup: on "Security credentials", select the device, choose "Resync" and enter two consecutive codes.
  • An error says you're not authorized to perform iam:DeleteVirtualMFADevice: this can happen after a cancelled setup. An administrator must delete the unassigned virtual MFA device first.
  • "Assign MFA device" fails for your IAM user: you may lack permission to manage your own MFA device. Ask your AWS administrator.

How to recover your Amazon Web Services account

AWS's IAM documentation doesn't describe backup codes. It recommends registering more than one MFA device (up to eight per user), so you can choose "Try another MFA method" at sign-in, and keeping a secure backup of the root user's QR code or secret key. If the root user's only device is lost, choose "Troubleshoot MFA", then "Sign in using alternative factors": AWS verifies the account email address and primary contact phone number. Then delete the old virtual MFA device, assign a new one and change the root password. Without that email or phone, contact AWS Support. IAM users must ask an administrator to deactivate the device, then set up Authenticator App - Novaz again.

Frequently asked questions

Is MFA mandatory for the AWS root user?
Yes, for every account type. If it isn't on yet, you must register MFA within 35 days of your first console sign-in attempt. IAM users have separate MFA settings.
Can one app hold several AWS accounts or users?
Yes. Each root or IAM user gets its own virtual MFA device, and Authenticator App - Novaz can store them all.
Which MFA types does AWS support?
Passkeys and security keys, virtual authenticator apps and hardware TOTP tokens. AWS recommends passkeys or security keys where possible, and SMS text message MFA can no longer be enabled.
I sign in through the AWS access portal. Is this the right guide?
Not quite. IAM Identity Center users choose "MFA devices" in the AWS access portal, then "Register device" and "Authenticator app".

Generate your Amazon Web Services codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Cloud guides

Novaz is not affiliated with, endorsed by, or sponsored by Amazon Web Services. Amazon Web Services and its logo are trademarks of their respective owner and are used here for identification only.