By default, AWS accounts are not allowed to add/remove their own access keys or multi-factor authentication tokens. To empower some of your users, you may be interested in adding a policy to allow them to do so.
I've named mine UsersManageOwnMFA-and-access-tokens and replaced my account