# Basic Best Practices After creating AWS Account

* AWS root user create လုပ်ပြီသွားတဲ့ အခါမှာ Security Best Practices အရ Root user ကိုMFA ( Multi-Factor Authentication) enable လုပ်ထားသင့်ပါတယ်။
    
* IAM user create လုပ်ထားသင့်ပါတယ်။ IAM user create လုပ်ပြီး အဲ့IAM user အတွက်permission သတ်မှတ်‌ပေးရပါမည်။ IAM user ကို လည်းMFA enable လုပ်ထားသင့်ပါသည်။
    
* Cost Control Best Practices အရ billing alerts နဲ့ free tier usage alerts တို့ကို enable လုပ်ထားသင့်ပါတယ်။
    
    ### **Enable MFA (MultiFactor Authentication) for the root user.**
    
    Log in with root user. Type your email address and password.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758687870781/d914cd73-5056-4019-8fee-bd7fe59e1f5a.png align="center")
    
    You will see the following page. Go to IAM dashboard to enable MFA.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758687907977/18994e2a-f046-4061-989d-1daa98cd1d43.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758687926904/73e51a9a-928a-482f-8690-9a69e8cca59a.png align="center")
    
    Click Add MFA.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758687954075/a0e5c1b7-8164-48f3-8467-d68986d892e9.png align="center")
    
    You will see the following page.
    
    “Device name” သတ်မှတ်‌‌ ‌‌ရပါမည်။Device options (3) မျိုး ထဲမှAuthenticator app ကို သုံးပြီး လုပ်ပြပေးသွားပါ့မယ်။
    
    Next&gt;
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758687971242/f4b6573b-a026-4b03-b5fa-2179868cd288.png align="center")
    
    No.1 အနေနဲ့ မိမိph ထဲမှာ Authenticator app install လုပ်ထားရပါမည်။
    
    (Google Authenticator app or Microsoft Authenticator or others…….)
    
    No.2 Show QR ကို နှိပ်ပါ။ ‌‌ပေါ်လာသောQR ကို Authenticator app မှScan လုပ်ပါ။
    
    No.3 Authenticator app မှ‌‌ ပေါ်လာသော Code No ကို ရိုက်ထည့်ပါ။ Code No 2 ခု ရိုက်ထည့်ပေးရပါမည်။
    
    Add MFA ကို နှိပ်ပါ။
    
* ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758687985781/b7f1cfdf-3be1-4917-b590-d50810ac1dda.png align="center")
    
* You will see the following page after Add MFA.
    
    IAM &gt; Dashboard
    
    ပုံမှာ ပြထားတာ လေးကတော့ Root user ရော IAM user ရော MFA Enable လုပ်ထားတာလေး ဖြစ်ပါတယ်။
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688038818/7a19c591-8296-4eb8-b7e3-d622848abc7e.png align="center")
    
    ### **Create IAM user and set permission. (AdministratorAccess permission for this lab)**
    
    Go to IAM dashboard and click Users. And then click “Create user”.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688255259/d429fada-a64b-4ddc-b4f5-f7d79d3686c8.png align="center")
    
    Type username and set password.
    
    (Check “Provide user access to the AWS Management Console- optional)
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688276758/9b4d4f13-b96e-451c-830c-664cda403c50.png align="center")
    
    Set “AdministratorAccess” permissions.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688287498/5c249d0d-4cd4-41bd-8715-beac8d86fe80.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688300910/ffa27595-2c21-40fc-9ad7-86f0477d4bb4.png align="center")
    
    Create user.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688315011/e6ec9a8a-7c47-484b-9adf-2ca88d54288d.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688323043/466cfd8b-6d3f-484a-8a0f-d7e49c629e8a.png align="center")
    
    ### **IAM user login with Account ID and create alias.**
    
    IAM user create လုပ်ပြီးသွားပြီ ဆိုတော့IAM user နဲ့ login ဝင်ကြည့်ပါမယ်။
    
    IAM user sign in အတွက်Account ID or alias လိုအပ်ပါတယ်။ Account alias မသတ်မှတ်ရ‌သေးတဲ့ အတွက် Account ID နဲ့ ဝင်ပါမယ်။ မိမိ သတ်မှတ်ခဲ့သောIAM username and password လိုပါမယ်။
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688376893/9ac8d5f6-e545-4570-b936-d5039c7f9e66.png align="center")
    
    You will see AWS management console home page after login.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688500165/e831d7d6-bce5-4c92-97d0-69d30c4b9ac9.png align="center")
    
    IAM user နဲ့ login ဝင်တဲ့ အချိန် တိုင်းAccount ID မှတ်ထားစရာ မလိုဘဲ မိမိ သတ်မှတ်ထားတဲ့Alias နဲ့ ဝင်ဖို့ အတွက် အခုAlias သတ်မှတ်ပါမယ်။
    
    Alias သတ်မှတ်ရန်အတွက်IAM page ထဲသို့ ဝင်ပါ။
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688515006/b112d874-7bd5-43c8-9cea-5e9e5e5405e9.png align="center")
    
    IAM &gt; Dashboard &gt; Account Alias Create ကို နှိပ်ပါ။
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688531083/bce141bc-84fd-43d3-9ac8-64cd19b4b0b7.png align="center")
    
    Set your alias.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688549530/3e81b208-eda4-4bc8-94b7-1a39971e22af.png align="center")
    
    Now you can login with your alias.
    
    ### **IAM user login with alias and access Billing Preferences page.**
    
    မိမိ create လုပ်ခဲ့‌သော alias, IAM username, password တို့နှင့် login ၀င်ပါ။
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688619062/31059793-5753-46ca-b20f-5b7503da2081.png align="center")
    
    Login ၀င်ပြီးတဲ့အခါ Console home page ရဲ့ ညာဘက်အပေါ်မှာ alias name, account id and IAM user name တို့ကို တွေ့ရပါလိမ့်မည်။
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688637216/407956c7-0f9d-4ec7-af56-79757fc4a1a0.png align="center")
    
    Go to the “Billing and Cost Management” Page.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688653205/6e79bcb4-6f94-43c3-bcbf-6fcb41e202e1.png align="center")
    
    And then go to “Billing preferences”. (Billing Preferences အကြောင်း နောက်တွင် အသေးစိတ်ထပ်ရှင်းပါမည်။) You will see the following page.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688678524/6cc610fc-546c-4c81-b287-2ceebe88918b.png align="center")
    
    * IAM user သည် Adminstrator access permission သတ်မှတ်ထားပေမယ် Billing Preferences page ထဲသို့ဝင်ကြည့် ရန်permissions လိုပါသည်။
        
    * Billing Preferences page ထဲ သို့ ဝင်ဖို့ လိုအပ်သည့် permissions ကို Root user ဘက်မှ Activated လုပ်ပေးရပါမည်။ ထို့ကြောင့် root user နှင့် login ပြန်ဝင်ပါမည်။
        
    * root user နှင့်login ဝင်ပြီး လျှင် ညာဘက် အပေါ် မှာ ရှိသော Account ID dropdown arrow ကို နှိပ်ပြီးAccount ကို နှိပ်ပါ။
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688706488/49a729a3-b743-4a03-ad98-56991bdf4092.png align="center")
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688714059/5155b31d-35f1-4718-86df-424fe5f52dc0.png align="center")
        
    
    Scroll down, you will see the “IAM user and role access to Billing information” is “Deactivated”.
    
    So, you need to activated. Go to Edit.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688745529/6adf31bb-5837-4a7d-9aca-4fcedbef07de.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688761371/2d30e1ac-a58c-4630-893c-e52a47f300c9.png align="center")
    
    Check “Activated IAM access” and click update.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688776988/ff752402-60c9-4d0c-aca9-2334cde04c56.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688783749/a36b7cf1-7041-4009-a041-9cd521caa0ed.png align="center")
    
    After Activated, login with IAM user and check Billing Preferences. You can access Billing Preferences page like that.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688796064/696624df-ba2b-45c0-932e-5054577c77e2.png align="center")
    
    ### **About Billing Preferences**
    
    Billing Preferences မှာ ဘာ တွေ လုပ်လို့ ရလဲဆိုရင်
    
    1. AWS မှာ ကိုယ်သုံးထားတဲ့service တွေက ဘယ်လောက်ကျလဲ ၊ ဘာservice တွေသုံးထားလဲဆိုတဲ့ Monthly invoice တွေကို PDF format နဲ့ကိုယ့် ဆီemail ပို့အောင် Invoice Delivery Preferences ကိုActivated လုပ်ပေးလို့ရပါတယ်။
        
    2. Free Tier Alerts နဲ့ ပတ်သတ်တဲ့ usage တွေကို ကိုယ့်ဆီEmail ပို့အောင် သတ်မှတ်ထားပေးလို့ရပါတယ်။
        
    3. CloudWatch billing alerts ‌‌‌တွေ လက်ခံလို့ ရအောင် enable လုပ်ပေးလို့ရပါတယ်။
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688832225/39b7f119-cb5b-4aa3-9643-fac989fcd714.png align="center")
        
    
    Click “Edit”.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688847883/8146f38f-c9a6-44e4-a699-27d7c71dde72.png align="center")
    
    Check “PDF invoices delivered by email” and then click Update.
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688864392/8be31159-5310-4c52-be3a-96ad69e29fdf.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688872183/e12f4bce-8e16-4ff1-ae5e-ae899c53859e.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688883150/ff9babf4-d352-46ff-beee-1f443e9a9814.png align="center")
    
    Setting up CloudWatch billing alarms
    
    * CloudWatch billing alarms ဘာလို့ သတ်မှတ်သလဲဆိုရင် ကိုယ့်ရဲ့ AWS total bill သည် ကိုယ်သတ်မှတ်ထားသော ပမာ ဏ(e.g - 5$) ထက်ကျော် ခဲ့ မယ်ဆိုရင် ကိုယ့်ဆီ Noti ပို့အောင် လို့ သတ်မှတ်ခြင်းဖြစ်ပါတယ်။
        
    * CloudWatch မှာ Billing Alarms သတ်မှတ်မယ်ဆိုရင် Region သည် N.Virginia (us-east-1) ဖြစ်မှ Billing Alarms သတ်မှတ်လို့ရပါမည်။
        
        Go to CloudWatch &gt; Alarms &gt; Create alarm
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688905963/8f80d36f-39cd-4f3d-909c-b6b75baa6d51.png align="center")
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688913430/93d6386d-8fb0-42cf-9c1a-b42f32968410.png align="center")
        
        Conditions မှာ
        
        Threshold type &gt; Static
        
        Greater than 5 USD သတ်မှတ်ပါမည်။ (မိမိလိုအပ်‌သော amount သတ်မှတ်နိုင်ပါသည်။)
        
        Next.
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688927646/b22caf38-0c8d-4b29-803c-fbf19d00a7b4.png align="center")
        
        Select “ Create new Topic” Topic name ပေးပါ။ Email ထည့်ပါ။ Click Create Topic.
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688943919/0a06d659-cd81-48e3-a0e0-713cb48e9438.png align="center")
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688951055/bd43a09d-6b00-4455-adac-43cf37c0836f.png align="center")
        
        ကိုယ့်ရဲ့ Email ထဲ ကို Confirm လုပ်ဖို့ mail ရောက်လာပါလိမ့်မယ်။ Confirm Subscription ကိုနှိပ်ပါ။
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688966039/1a8080b4-ded0-4f9e-a58e-be1e4cdd009e.png align="center")
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688972592/e3189083-5359-4fa2-a063-be36938d1b45.png align="center")
        
        Alarm name ‌‌‌‌ ‌သတ်မှတ်‌ရပါမည်။
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758688990389/d4a02598-ff85-4d0c-979f-b331bd260279.png align="center")
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758689000301/0b660660-0512-4900-b809-4f2d592a0af0.png align="center")
        
        ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1758689007687/5464ea61-9f9b-49bf-b5f5-bb75df3ac76e.png align="center")
