Your organization has offices around the world and some employees travel between offices. How should their accounts be setup?
IAM is a global service and all users that are created are able to login to the AWS Management Console from any location.
You do not create separate IAM accounts in different regions as IAM is a global service.
There is no such thing as setting the account as “global”.
Enabling multi-factor authentication is a good security practice but not necessary to enable users to travel to different locations.
References: