I have a small, single-user AWS account with roughly $10 in average monthly costs, mostly for domain registration, a few Lambda functions, DynamoDB, and Route 53. I use 1Password for my credentials and keep the root account separate from the IAM administrator account I use every day. Both accounts have MFA enabled, and I can sign in to the IAM account without any trouble. However, I recently needed to make some account or organization changes and discovered that the root password is accepted but every MFA code is rejected. I have not signed in to the root account for a long time, and I do not currently have a paid AWS Support plan. What is the best way to recover access or reset the root account MFA?
2 Answers
You can open an Account and Billing support case for free, even without a paid support plan. Start from the administrator account and provide the root account ID. AWS will likely ask for account ownership and identity verification, and resolution may take a little while, but this is the proper route if the reset process does not work.
The MFA device may have drifted out of sync after sitting unused for a long time. Try AWS’s root-user MFA troubleshooting and reset process first. If you still have access to the registered email and other account details, you may be able to disable or replace the MFA device through the recovery flow.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures