Planning ahead for your AWS accounts

Lifetime transfer options and steps to take now for Amazon Web Services, Inc. accounts

Amazon Web Services, Inc.

Developer & Cloud

aws.amazon.com
Amazon Web Services, Inc. logo

AWS Support

AWS Support (no dedicated estate or bereavement channel)

Verified Sep 2026

Transfer of accounts after death is not guaranteed under Amazon Web Services, Inc.'s terms. Lifetime planning offers a more reliable way to manage and share accounts while the account is active.

How to protect your AWS accounts

8 lifetime planning steps for your AWS accounts:

1
For a standalone AWS account, note that AWS documents closure only by the root user and that AWS Support will not close the account for an estate, so whoever settles the estate needs a lawful route to the root user email address and any MFA device. Record that the account exists, its account ID, and what it is used for.
2
For production workloads, place the account inside AWS Organizations in All Features mode. An authorized IAM user or role in the management or delegated admin account can then close member accounts and update the member root email without the member account's root credentials, which removes the single point of failure a standalone account creates.
3
Maintain an inventory of what is running and what it costs. Compute instances, databases, storage, Reserved Instances, Savings Plans, and Marketplace subscriptions keep billing until the account is closed, and Reserved Instances, Savings Plans, and Marketplace subscriptions continue to invoice after closure until they expire or are canceled.
4
Record where important data and snapshots live and back them up on a schedule. AWS deletes remaining content and resources after the 90-day post-closure period, so anything not exported beforehand is gone.
5
Document IAM users and roles separately from the root user. IAM identities can run day-to-day operations but cannot close a standalone account or perform other root-only account tasks, so they do not substitute for root access in an estate.
6
List any domains registered through Amazon Route 53 in the account, and check whether the root user email address itself uses one of them. AWS suspends the domains on a closed account after up to five days of daily emails, then deletes Amazon Registrar domains after 30 days or releases Gandi-registered domains to Gandi. Where the root email depends on a domain registered in the same account, AWS documents moving the domain to another AWS account or moving the root email to an outside domain first — otherwise closure breaks the mailbox the account recovers through.
7
Note the account alias and any hardware MFA token. AWS states a closed account's email address and account alias cannot be reused on another AWS account, and that hardware TOTP token devices cannot be associated with another user after permanent closure.
8
Plan AWS alongside the rest of the Amazon ecosystem. The consumer Amazon account (Kindle, Prime Video, Photos, Alexa, gift cards, Amazon Pay) follows a separate process — see the Amazon estate guide.

Family sharing

AWS has no consumer family-sharing or pooling feature. The organizational equivalent is AWS Organizations: multiple AWS accounts are combined into one organization for central management, with a management account and optional delegated administrator accounts. In All Features mode, authorized IAM users or roles in the management or delegated admin account can close member accounts and update member account settings (including the root user email address, account name, contact information, alternate contacts, and Regions) without the member account's root credentials. Centralized root access additionally lets an organization remove member account root credentials entirely — AWS states such member accounts "can't sign in to their root user or perform password recovery for their root user unless account recovery is enabled" — and lets the management account or delegated administrator run an "Allow password recovery" privileged task when root access to a member account is needed. None of this applies to a standalone account, which can only be acted on by its own root user. Alternate contacts are a notification list and confer no account authority.

Should you save your passwords for your family?

Some people store account passwords so a family member can sign in later. The practice has three practical limits:

  • Two-factor authentication often blocks it. Most accounts require a second factor — a code sent to a phone, an authenticator app, a passkey, or a physical key. A saved password alone frequently does not grant access, and the recovery codes that would are easy to lose or let go stale.
  • It usually conflicts with the platform's terms. Most operators prohibit account sharing and signing in as another person, including after a death. Stored credentials are not the operator's recognized access path, and using them can violate the terms of service.
  • Operators provide other paths. Where an operator offers a designation tool — Apple's Legacy Contact, Google's Inactive Account Manager, a beneficiary designation — that mechanism grants access the operator recognizes. A password manager's own emergency-access or legacy feature passes credentials through a controlled process. Digital assets named in a will or trust give a fiduciary authority under each state's Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA).

Frequently asked questions

For a standalone account, a lawful route to root access has to remain reachable by whoever settles the estate, because AWS documents closure only by the root user and AWS Support will not do it for an estate. For production workloads, placing the account inside AWS Organizations in All Features mode lets an organization admin close member accounts without the member root credentials. An inventory of what is running and what it costs, IAM users and roles documented separately from the root user (they cannot close a standalone account), a note of any Route 53 domain the root email depends on, and regular backups of important data and snapshots address the rest — AWS deletes remaining resources after the 90-day post-closure period.

A lawful route to the root user email address, and to any MFA device or recovery method attached to it — recorded alongside the account ID, not as a shared password. AWS documents closure of a standalone account only by the root user, and AWS Support will not close one for an estate. IAM users and roles can run day-to-day operations but cannot close a standalone account or perform other root-only tasks. For production workloads, placing the account in AWS Organizations in All Features mode lets an organization admin close it centrally without the member root credentials, removing the single point of failure a standalone account creates. AWS also states that MFA is not removed automatically when an account is closed, and that a hardware TOTP token cannot be associated with another user after permanent closure.

Listing the AWS account in an estate inventory identifies it for a fiduciary, who works through the operator's official channels to manage or close it.

AWS does not support beneficiary designations. Unlike financial accounts, there is no way to name a beneficiary on this type of account.

SimplyTrustSimplyTrust Editorial·

Sources

Data sourced from Amazon Web Services, Inc. primary sources (8 pages reviewed). How we research.

More estate planning resources

Explore related tools and documents to complete your estate plan.

How Much Does Probate Cost?

Estimate attorney fees, executor fees, court costs, and timeline for probating an estate in your state. See if the estate qualifies for simplified probate procedures.

Use Calculator

Who Inherits Without a Will?

Find out who inherits your estate and how much they get if you die without a will. Based on your state's intestate succession laws.

Use Calculator

How Much Are Estate & Inheritance Taxes?

Calculate federal estate tax, state estate tax (12 states + DC), and inheritance tax (5 states) for an estate or trust.

Use Calculator

What Does Estate Planning Actually Cost?

See the true cost of estate planning. Compare SimplyTrust, Trust & Will, LegalZoom, and attorneys including life events like marriage, divorce, and having children.

Compare Costs

How Much Does a Revocable Living Trust Cost?

Compare the cost of creating a revocable living trust. See how SimplyTrust, Trust & Will, LegalZoom, and attorneys compare over 5 years including life events.

Compare Costs

How Much Does a Will Cost?

Compare the cost of creating a will. See document costs plus probate fees your heirs will pay. Compare SimplyTrust, Trust & Will, LegalZoom, and attorneys.

Compare Costs