Amazon Web Services 2FA Setup Guide
Your AWS sign-in controls the servers, data and billing in your account, so a password alone shouldn't be enough. AWS calls the feature multi-factor authentication (MFA) and an authenticator app a "virtual MFA device", and it accepts six-digit codes from apps like Authenticator App - Novaz for the root user and IAM users.
A Amazon Web Services account can hold your files and backups of everything else, so protect it with 2FA. Besides an authenticator app, Amazon Web Services also offers a hardware token and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, Amazon Web Services also supports hardware security keys.
2FA methods Amazon Web Services supports
- Authenticator app (TOTP)
- Hardware token
- Security key (U2F / WebAuthn)
Before you start
- Root user: the account email address and password, plus access to that email and the account's primary contact phone number for recovery
- IAM user: the account ID or alias, your user name and password, and permission to manage your own MFA device; otherwise an administrator assigns it and needs your phone to finish
- Authenticator App - Novaz installed on your iPhone or iPad
- The AWS Management Console open on a computer, so your phone can scan its QR code
Part 1: Turn on 2FA in Amazon Web Services
- 1
Open Security credentials
Sign in to the AWS Management Console. On the right side of the navigation bar, choose your account name (or IAM user name), then choose "Security credentials". Administrators can instead pick a user under "Users" in the IAM console and open the "Security credentials" tab.
- 2
Choose Assign MFA device
In the "Multi-factor authentication (MFA)" section, choose "Assign MFA device".
- 3
Name the device and choose Authenticator app
Type a "Device name", choose "Authenticator app" and then choose "Next".
- 4
Show the QR code
Choose "Show QR code", or "Show secret key" if you'd rather type the key. Leave the page open while you pick up your phone.
Part 2: Add Amazon Web Services to Authenticator App - Novaz
- 5
Add AWS in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code. If you chose "Show secret key", choose to enter a setup key and type it exactly as AWS shows it. Then tap "Save".
- 6
Watch for two codes in a row
Authenticator App - Novaz now shows a six-digit code for AWS. You'll need this code and the next one, which appears within 30 seconds.
Part 3: Confirm and finish
- 7
Enter two consecutive codes
Type the current code into "MFA code 1", wait for the next code, and type it into "MFA code 2". Choose "Add MFA" straight away: codes submitted too late can leave the device out of sync.
- 8
Know when AWS will ask for a code
At each console sign-in, AWS shows a second page after your password: type the code from Authenticator App - Novaz into the "MFA code" box.
- 9
Save a way to recover your account
If Amazon Web Services offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Amazon Web Services recovers accounts before you need it.
If something goes wrong
- AWS rejects your code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time). After several failed tries, AWS prompts you to resynchronize the device.
- Codes stop working after setup: on "Security credentials", select the device, choose "Resync" and enter two consecutive codes.
- An error says you're not authorized to perform iam:DeleteVirtualMFADevice: this can happen after a cancelled setup. An administrator must delete the unassigned virtual MFA device first.
- "Assign MFA device" fails for your IAM user: you may lack permission to manage your own MFA device. Ask your AWS administrator.
Checked against Amazon Web Services's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Assign a virtual MFA device in the AWS Management Console – AWS Identity and Access Management ↗
- Enable a virtual MFA device for the root user (console) – AWS Identity and Access Management ↗
- Recover an MFA protected identity in IAM – AWS Identity and Access Management ↗
- AWS Multi-factor authentication in IAM – AWS Identity and Access Management ↗
- MFA enabled sign-in – AWS Identity and Access Management ↗
How to recover your Amazon Web Services account
AWS's IAM documentation doesn't describe backup codes. It recommends registering more than one MFA device (up to eight per user), so you can choose "Try another MFA method" at sign-in, and keeping a secure backup of the root user's QR code or secret key. If the root user's only device is lost, choose "Troubleshoot MFA", then "Sign in using alternative factors": AWS verifies the account email address and primary contact phone number. Then delete the old virtual MFA device, assign a new one and change the root password. Without that email or phone, contact AWS Support. IAM users must ask an administrator to deactivate the device, then set up Authenticator App - Novaz again.
Frequently asked questions
- Is MFA mandatory for the AWS root user?
- Yes, for every account type. If it isn't on yet, you must register MFA within 35 days of your first console sign-in attempt. IAM users have separate MFA settings.
- Can one app hold several AWS accounts or users?
- Yes. Each root or IAM user gets its own virtual MFA device, and Authenticator App - Novaz can store them all.
- Which MFA types does AWS support?
- Passkeys and security keys, virtual authenticator apps and hardware TOTP tokens. AWS recommends passkeys or security keys where possible, and SMS text message MFA can no longer be enabled.
- I sign in through the AWS access portal. Is this the right guide?
- Not quite. IAM Identity Center users choose "MFA devices" in the AWS access portal, then "Register device" and "Authenticator app".
Generate your Amazon Web Services codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Cloud guides
Novaz is not affiliated with, endorsed by, or sponsored by Amazon Web Services. Amazon Web Services and its logo are trademarks of their respective owner and are used here for identification only.


