# Multi-Factor Authentication - MFA

Users have access to your account and can possibly change configurations or delete resources in your AWS account

* You want to protect your Root Accounts and IAM users
* MFA = password you know + security device you own

<figure><img src="https://1722711354-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwNXdoUkfmcozr29fRrfb%2Fuploads%2FAtLbwRbS0lpTp5fnldaJ%2Fimage.png?alt=media&#x26;token=c71a71b8-0aca-4df3-921d-c3b38dd2554b" alt=""><figcaption></figcaption></figure>

• Main benefit of MFA: if a password is stolen or hacked, the account is not compromised

<figure><img src="https://1722711354-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwNXdoUkfmcozr29fRrfb%2Fuploads%2F76RxnYMPwDjlbv6WEiw7%2Fimage.png?alt=media&#x26;token=d98dd277-a14f-41a0-bbd9-2e784f107673" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1722711354-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwNXdoUkfmcozr29fRrfb%2Fuploads%2FPiF7LvqE0mgb2iuQm9tu%2Fimage.png?alt=media&#x26;token=01029773-0232-4e9a-b57c-dc64ad6d1621" alt=""><figcaption></figcaption></figure>
