Planning ahead for your AWS accounts

Lifetime transfer options and steps to take now for Amazon Web Services, Inc. accounts

Amazon Web Services, Inc.

Developer & Cloud

aws.amazon.com
Amazon Web Services, Inc. logo

AWS Support

AWS Support (no dedicated estate or bereavement channel)

Verified Jul 2026

Transfer of accounts after death is not guaranteed under Amazon Web Services, Inc.'s terms. Lifetime planning offers a more reliable way to manage and share accounts while the account is active.

How to protect your AWS accounts

7 lifetime planning steps for your AWS accounts:

1
For a standalone AWS account, note that AWS documents closure only by the root user and that AWS Support will not close the account for an estate, so whoever settles the estate needs control of the root user email address and any MFA device. Record that the account exists and what it is used for.
2
For production workloads, place the account inside AWS Organizations in All Features mode. An authorized IAM user or role in the management or delegated admin account can then close member accounts and update the member root email without the member account's root credentials, which removes the single point of failure a standalone account creates.
3
Maintain an inventory of what is running and what it costs. Compute instances, databases, storage, Reserved Instances, Savings Plans, and Marketplace subscriptions keep billing until the account is closed, and Reserved Instances, Savings Plans, and Marketplace subscriptions continue to invoice after closure until they expire or are canceled.
4
Record where important data and snapshots live and back them up on a schedule. AWS deletes remaining content and resources after the 90-day post-closure period, so anything not exported beforehand is gone.
5
Document IAM users and roles separately from the root user. IAM identities can run day-to-day operations but cannot close a standalone account or perform other root-only account tasks, so they do not substitute for root access in an estate.
6
List any domains registered through Amazon Route 53 in the account. AWS suspends the domains on a closed account after up to five days of daily emails, then deletes Amazon Registrar domains after 30 days or releases Gandi-registered domains to Gandi when the account is permanently closed.
7
Plan AWS alongside the rest of the Amazon ecosystem. The consumer Amazon account (Kindle, Prime Video, Photos, Alexa, gift cards, Amazon Pay) follows a separate process — see the Amazon estate guide.

Family sharing

AWS has no consumer family-sharing or pooling feature. The organizational equivalent is AWS Organizations: multiple AWS accounts are combined into one organization for central management, with a management account and optional delegated administrator accounts. In All Features mode, authorized IAM users or roles in the management or delegated admin account can close member accounts and update member account settings (including the root user email address) without the member account's root credentials. Centralized root access additionally lets an organization remove member account root credentials entirely and perform root password recovery on a member account. None of this applies to a standalone account, which can only be acted on by its own root user.

Should you save your passwords for your family?

Some people store account passwords so a family member can sign in later. The practice has three practical limits:

  • Two-factor authentication often blocks it. Most accounts require a second factor — a code sent to a phone, an authenticator app, a passkey, or a physical key. A saved password alone frequently does not grant access, and the recovery codes that would are easy to lose or let go stale.
  • It usually conflicts with the platform's terms. Most operators prohibit account sharing and signing in as another person, including after a death. Stored credentials are not the operator's recognized access path, and using them can violate the terms of service.
  • Operators provide other paths. Where an operator offers a designation tool — Apple's Legacy Contact, Google's Inactive Account Manager, a beneficiary designation — that mechanism grants access the operator recognizes. A password manager's own emergency-access or legacy feature passes credentials through a controlled process. Digital assets named in a will or trust give a fiduciary authority under each state's Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA).

Frequently asked questions

For a standalone account, root access has to remain reachable by whoever settles the estate, because AWS documents closure only by the root user and AWS Support will not do it for an estate. For production workloads, placing the account inside AWS Organizations in All Features mode lets an organization admin close member accounts without the member root credentials. An inventory of what is running and what it costs, IAM users and roles documented separately from the root user (they cannot close a standalone account), and regular backups of important data and snapshots address the rest — AWS deletes remaining resources after the 90-day post-closure period.

Control of the root user email address, and of any MFA device or recovery method attached to it. AWS documents closure of a standalone account only by the root user, and AWS Support will not close one for an estate. IAM users and roles can run day-to-day operations but cannot close a standalone account or perform other root-only tasks. For production workloads, placing the account in AWS Organizations in All Features mode lets an organization admin close it centrally without the member root credentials, removing the single point of failure a standalone account creates. AWS also states that MFA is not removed automatically when an account is closed.

Listing the AWS account in an estate inventory identifies it for a fiduciary, who works through the operator's official channels to manage or close it.

AWS does not support beneficiary designations. Unlike financial accounts, there is no way to name a beneficiary on this type of account.

SimplyTrustSimplyTrust Editorial·

Sources

Data sourced from Amazon Web Services, Inc. primary sources (7 pages reviewed). How we research.