
Secure Foundation π - Setting Up Your AWS Free Tier Account
Learn to create and secure your AWS Free Tier account with MFA, IAM users, and budget alerts. This guide walks you through AWS safely within free limits
Welcome to Day 1 of the AWS Builder Challenge #2Β π! Today you will create your first AWS account and set it up properly from the start. Don't worry if you've never used AWS before, we will guide you through each step.
In about 30 minutes, you'll create a free account plan that is secure, cost-controlled, and ready for building. We're not just creating an account, we are setting up the security and billing protections that will keep you safe as you learn.
This means enabling multi-factor authentication, creating an admin user for daily work, and setting up alerts so so you'll track your costs and get notified if they start adding up. The goal is to build your very own personal website this week within the Free Tier limits.
By the end of today, you'll have your AWS account ready to start building on. Let's get started.
What you will accomplish today
- Create your AWS Free Tier account
- Enable Multi-Factor Authentication (MFA) for the root user
- Set up an IAM admin user for daily operations
- Create a budget with alerts when you approach or exceed your spending limit ($5)
- Understand how AWS Free Tier works
What you will need:
- Computer π»
- Email address π§
- Phone (for account verification and MFA setup) π
- Credit card (required for account verification, but won't be charged for Free account plan usage) π³
Step 1: Create your AWS Free Tier account π
Letβs get started! We're going to create your very first AWS account.
- Create your free tier account - Go to the AWS Free Tier pageΒ and click on "Create a Free account"
- Enter your details - AWS needs your email address for signing in, a password, and an account name.
- Verify your email - Check your inbox for a verification code and enter it when prompted.
- Choose a Free account plan - You'll see two options: Free account plan or Paid account plan. Pick Free account plan β this gives you up to 6 months to explore with $100 in credits and no charges.
- Add your personal info - Fill in your contact details. Choose "Personal" when asked about account type.
- Payment method - Here's where you add that credit card we mentioned. AWS needs this to verify you're a real person, but with the Free account plan, you won't be charged during your 6-month period or until your credits expire.
- Phone verification - AWS will call or text you with a PIN. Enter it when you get it.
You'll know you're done when: You see a "Congratulations" page and receive $100 in credits automatically added to your account.
Step 2: Secure your account root user with MFA π
Now that you have your AWS account, letβs secure it. Your root user has complete access to everything in your AWS account - all services, billing, and even the ability to close the account. That's why it's important to secure it right away and then avoid using it for everyday tasks.
We will use MFA (Multi-Factor Authentication) to add an extra layer of security to your root user. MFA ensures that even if someone gets your password, they can't access your account without your phone.
- Sign in to your AWS account - Go to aws.amazon.comΒ and click on "Sign in to console" in the top right. Use the email and password you just created.
- Find your account menu - Once you're in the AWS Console, look for your account id and name in the top right corner and click on it.
- Go to security credentials - From the account dropdown menu, select "Security credentials"
- Set up MFA - Look for the "Multi-factor authentication (MFA)" section and click "Assign MFA device"
- Choose "Authenticator app" - First, give your device a name (like "MyPhone" or "iPhone") in the "Device name" field, then select "Authenticator app" from the device options and click "Next"
- Follow the setup wizard - Use an authenticator app like Google Authenticator, Microsoft Authenticator, or Twilio Authy:
- Scan the QR code with your authenticator app
- Enter two consecutive codes from your app
- Click "Add MFA"
You'll know you're done when: You see "MFA device successfully assigned" and your Security credentials page shows an active MFA device.
Step 3: Create your IAM user π€
β οΈ Important: During this step, you'll see options for "IAM Identity Center" - please don't set that up right now as it might upgrade your account out of the Free account plan. We'll guide you to select "IAM user" instead.
Now that your root account is secure, let's create a user for your daily work.
IAM (Identity and Access Management)Β is AWS's system for managing who can access your account and what they can do. AWS recommends avoiding the root account for everyday tasks - instead, you should create an IAM user with admin permissions for regular use.
Think of this like having a master key (root account) that you keep in a safe, and a regular key (IAM user) that you use every day. Both can unlock your house, but if you lose the regular key, your master key is still safe.
- Go to IAM - In the AWS Console, search for "IAM" in the top search bar and click on it
- Create a new user - In the IAM dashboard, click "Users" in the left sidebar, then click "Create user"
- Set user details - Enter a username (like "admin" or your name) and check "Provide user access to the AWS Management Console"
- Enable console access - Check the box for "Provide user access to the AWS Management Console" so your user can sign in to AWS.
- Choose user type - When you see the "User type" options, select "I want to create an IAM user" (not "Specify a user in Identity Center"
β οΈ Please follow this carefully: Don't set up IAM Identity Center right now, as it might automatically upgrade your account out of the Free account plan. We want to keep things simple and stay within your free limits for this challenge. - Set console password - You can choose "Autogenerated password" (AWS will create one for you). Click "Next"
- Set permissions - You'll see three permission options. Keep "Add user to group" selected (it's the default and recommended approach)
- Create an admin group - Since you don't have any groups yet, click "Create group" to make a new one
- Configure the group - In the popup:
- Enter "Administrators" as the group name
- In the permissions policies list, check the box next to "AdministratorAccess" (it provides full access to AWS services)
- Click "Create user group"
- Select your group - Back on the permissions page, you'll see your new "Administrators" group in the list. Check the box next to "Administrators" to select it, then click "Next"
- Review and create - Review all your settings on the summary page, then click "Create user"
- Save your credentials - On the final page, you'll see:
- Console sign-in URL (save this!)
- Your username
- Your password (click "Show" to see it, or download the .csv file)
Important: This is the only time you can see the autogenerated password, so save it now!
You'll know you're done when: You see "User created successfully" and can copy your sign-in details. From now on, use this IAM user for all your daily AWS work, including the rest of this challenge
Note: Stay logged in as the root user for now - we need to enable billing access for your IAM user in the next step before switching users.
Step 4: Switch to your new admin user π
Before we can switch to your new IAM user, we need to give it access to billing information. By default, only the root user can see billing details - let's change that so your admin user can create budgets.
Part A: Enable billing access (while logged in as root user)
- Go to Account settings - In the AWS Console, click on your account id in the top right, then select "Account"
- Find IAM billing access - Scroll down until you find the section "IAM User and Role Access to Billing Information", then click "Edit"
- Activate IAM access - Check the box next to "Activate IAM Access" to enable access to the Billing and Cost Management console
- Save changes - Click "Update" to save your settings. You'll see a message confirming "IAM user/role access to billing information is activatedβ
Part B: Switch to your IAM user
- Sign out of root account - Click on your account name in the top right and select "Sign Out"
- Sign in with your IAM user - Use the Console sign-in URL you saved earlier, along with your IAM username and password
- Update your password - Since you chose "Users must create a new password at next sign-in", AWS will prompt you to create a new password.
You'll know you're done when: You're signed in as your IAM user (you'll see your username in the top right instead of the account name) and can access the Billing console.
This allows your IAM admin user to create and manage budgets, which is essential for the next step. Without this, only the root user could access billing information.
Step 5: Setup a budget π°
Now let's set up a budget to track your spending and get alerts if you approach your $5 limit. This will help you stay within the Free Tier and avoid unexpected charges. π Plus, creating a budget is one of the activities that earns you additional Free Tier credits!
- Go to Billing and Cost Management - In the AWS Console, click on your account name in the top right, then select "Billing and CostManagementβ
- Navigate to Budgets - In the left navigation pane, click "Budgets"
- Create a new budget - Click "Create budget" at the top of the page
- Choose a template - Under "Budget setup", select "Use a template (simplified)"
- Select monthly cost budget - Under "Templates", choose "Monthly cost budget" (this notifies you if you exceed or are forecasted to exceed your budget amount)
- Set your budget details:
- Budget name: Enter something like "Monthly Budget"
- Budgeted amount: Enter "$5.00"
- Email recipients: Enter your email address to receive alerts
- Create the budget - Click "Create budget"
You'll know you're done when: You see your new budget listed in the Budgets dashboard.
This budget will alert you when you hit 85% ($4.25), when you're forecasted to exceed $5, and when you actually exceed $5. Even though you have $100 in credits, this acts as an early warning system to catch unexpected charges. As a bonus, completing this activity earns you additional Free Tier credits!
Important: Budget alerts aren't real-time - they're updated up to three times per day, so there can be delays between when you incur charges and when you receive notifications.
Step 6: Get to know how the AWS Free Tier works π€
Understanding the basics of your free account plan will help you make the most of your 6-month learning period:
Your Free Account Plan Duration β°
- Lasts up to 6 months from when you created your account
- You get $100 in credits automatically, plus you can earn up to $100 more by completing activities
- The plan expires when you either hit 6 months OR use up all your credits (whichever comes first)
- No charges will be incurred during your free account plan period
Monitoring Your Usage π
Check your credit balance and expiration date in the Cost and Usage widget on your AWS Console home page. AWS will also send you periodic email alerts about your credit balance and approaching expiration, plus your budget alerts from Step 5 help track spending.
What happens when my free plan expires? π€
When your free plan expires, your account closes automatically and you lose access to your resources and data. Don't panic though - AWS keeps your data safe for 90 days, giving you time to upgrade to a paid plan if you want to restore access. If you don't upgrade within those 90 days, everything gets permanently deleted.
Service Access π οΈ
You have access to most AWS services during your free plan, but some high-cost services are restricted to prevent accidentally consuming all your credits. Plus, over 30 services offer "Always Free" monthly limits that continue even after your plan expires.
β οΈ Important Warning: Actions that end your Free Plan
Some actions will immediately upgrade your account to a paid plan and end your free account plan, including creating or joining an AWS Organization. This can happen inadvertently through IAM Identity Center setup. We'll help you avoid these throughout this challenge.
For complete and updated information, the AWS Free Tier FAQs pageΒ is the source for all details about your free account plan.
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article