Developer tools · reviewed 2026-08-27

AWS login, two-factor settings, and account recovery

A source-checked route to signin.aws.amazon.com, with the documented security menu, the recovery sequence, and the AWS-specific requests that should make you stop.

Open official AWS signin.aws.amazon.com

You are leaving login.com. We never ask for or receive account credentials.

Independent guide. login.com is an independent educational resource. We are not affiliated with, endorsed by, or connected to the services described. Always sign in only on the service's own official website.

Last reviewed: 2026-08-27 · Report a change

01 · verified destination

Start on signin.aws.amazon.com

A careful AWS sign-in begins before any credential prompt. Confirm the destination, recognize the account identifier the service expects, and pause when a redirect does not make sense.

The verified account destination is https://signin.aws.amazon.com/. A redirect can be legitimate when AWS documents a connected identity provider, but the final request should still match the sign-in method you originally chose. AWS root users, IAM users, and IAM Identity Center users do not use one interchangeable sign-in route. Identify the account type and account or portal before entering credentials.

AWS account note: The generic AWS sign-in page is a routing start, not proof that root, IAM, and Identity Center credentials are interchangeable. Keep that product-specific distinction in mind before changing credentials or opening a second account.

People also describe this destination as “aws login” or “aws console login” or “amazon web services sign in.” Those phrases are search clues, not domains; the verified AWS host remains signin.aws.amazon.com.

Scope: this developer tools guide covers AWS access for the AWS root user, IAM user, or IAM Identity Center identity for the intended account or organization, including the search names aws login, aws console login, amazon web services sign in, and no other host substitutes for signin.aws.amazon.com.

Official host
signin.aws.amazon.com
Account identifier
the AWS root user, IAM user, or IAM Identity Center identity for the intended account or organization
2FA evidence
Documented
Checked
2026-08-27

02 · safe sign-in sequence

Sign in to AWS without following a lure

  1. 01

    Open https://signin.aws.amazon.com/ and wait for the verified signin.aws.amazon.com host to load.

  2. 02

    Read the complete address before continuing; do not rely on the AWS logo, page colors, or a padlock alone.

  3. 03

    Choose the normal AWS account route for the AWS root user, IAM user, or IAM Identity Center identity for the intended account or organization.

  4. 04

    Use the same identity-provider or account method originally attached to this AWS account.

  5. 05

    Complete AWS's configured second factor only because you initiated this sign-in.

  6. 06

    After access, review root-user sign-in and remove sessions, devices, or connected apps you do not recognize.

A password manager that does not recognize the host can be a useful warning. Do not force-fill or copy a password merely because the page resembles AWS. If the expected account is missing, return to signin.aws.amazon.com and choose the original provider instead of creating a duplicate profile.

Check a suspicious AWS link without opening it →

03 · documented security path

Turn on extra verification for AWS

The menu trail matters for AWS: it helps separate a real account control from a fake setup QR code or an obsolete third-party tutorial.

Settings path AWS console → Security credentials for the root or IAM user, or the organization's IAM Identity Center settings

The official material reviewed for this edition names the methods below. It can still limit a method by region, subscription, device, organization policy, or account type. An administrator-controlled identity provider may replace AWS's personal setting.

  • Authenticator app
  • Security key

Finish setup while a trusted AWS session remains open. Register a separate backup when allowed, save recovery material away from the daily device, and test a fresh sign-in before deleting the old authenticator.

Read AWS's official security material ↗

04 · what to look for

AWS controls named in the reviewed material

  • 01root-user sign-in
  • 02IAM user access
  • 03multi-factor authentication devices

Treat these names as navigation landmarks, not as a guarantee that every AWS user sees the same screen. Personal, managed, child, regional, and enterprise accounts can differ. The official source list at the end of this guide records exactly what was checked.

05 · service-specific lures

Two AWS phishing patterns to reject

Context is as important as design. A polished AWS notice can still be hostile when it arrives unexpectedly or asks for a secret that legitimate support should not need.

Pattern 1

a billing, abuse, access-key, or service-suspension alert that opens an AWS console lookalike.

Pattern 2

a supposed AWS employee asking for a root password, MFA code, access key, secret key, or remote shell session.

Open signin.aws.amazon.com independently and look for the same event inside the account. HTTPS and a familiar logo are not ownership evidence. Never give a live verification code to a caller or chat contact, approve an unexpected prompt, expose a backup code, paste a browser cookie, or install remote-control software to “resolve” a AWS warning.

Review root-user protection, IAM identities, MFA devices, access keys, roles, billing contacts, and CloudTrail events after suspicious access.

06 · locked-account plan

Recover AWS through the documented route

When AWS refuses a sign-in, keep the current trusted device online. A recognized session can be more useful than repeated reset attempts from a new browser or network.

Use the AWS sign-in troubleshooting path for the correct identity type. Preserve the account ID, root email, organization portal, and support plan before resetting or replacing an MFA device.

After access returns, change any reused password, revoke unknown sessions and connected apps, inspect recovery email and phone details, and replace any backup code that may have been seen. Check service-owned activity such as projects, messages, purchases, files, or profile changes before assuming the incident is over.

Open the official AWS help center ↗

07 · passkey status

Passkeys for AWS: not yet verified

This guide does not claim current passkey support for AWS. A security key, device approval, or biometric prompt is not automatically a passkey, and an old product announcement is not enough to establish current availability.

Check AWS's live account settings and official help. If no passkey control appears, use the strongest documented method available and revisit the setting after the service publishes a change.

For the underlying technology and recovery trade-offs, read What is a passkey?

08 · answers for this service

AWS login and security FAQ

How do I reach AWS's security controls?

Begin on signin.aws.amazon.com, then follow AWS console → Security credentials for the root or IAM user, or the organization's IAM Identity Center settings. This path was checked against the official documentation listed below; managed, regional, or app-only accounts can present different controls.

What did this guide verify for AWS?

AWS's reviewed material names root-user sign-in, IAM user access, multi-factor authentication devices. The guide keeps plan, device, organization, and evidence boundaries visible instead of treating every feature as universal.

If AWS locks me out, what should I do first?

Use the AWS sign-in troubleshooting path for the correct identity type. Preserve the account ID, root email, organization portal, and support plan before resetting or replacing an MFA device. Do not replace that official flow with a phone number, direct message, or paid recovery offer found in search results.

Which fake AWS request is especially risky?

Treat a supposed AWS employee asking for a root password, MFA code, access key, secret key, or remote shell session as hostile until the same event appears inside signin.aws.amazon.com. Never forward a password, live code, backup code, session token, or recovery secret to resolve it.

09 · sources checked

Official AWS sources

Only service-owned account pages and help documentation support the claims above. “Checked” records the editorial review date; it is not a promise that AWS will never change the interface.

  1. AWS sign in Official AWS sign-in routing destination · checked 2026-08-27
  2. What is AWS Sign-In? Differences among root, IAM, and IAM Identity Center sign-in · checked 2026-08-27
  3. Multi-factor authentication in AWS AWS-supported MFA devices and identity-specific configuration · checked 2026-08-27
  4. Troubleshooting AWS sign-in issues Official troubleshooting for AWS sign-in problems · checked 2026-08-27

10 · continue safely