They need to get serious about security usability
The app is fairly good - reasonable features, decent reporting - but I never use it because it doesnt store login credentials, meaning I have to enter a strong password and MFA token every single time.
Good security practice would use a durable login token for read-only operations and only require strong authentication for disruptive operations or anything which would incur new charges.
acdha about
AWS Console