ram-user-role-no-product-admin-access

Updated at:

Checks whether a Resource Access Management (RAM) role has administrator or cloud service administrator permissions. Roles without such permissions are evaluated as Compliant.

Scenarios

Enforces the principle of least privilege (PoLP) for RAM role permissions to prevent security risks from excessive access.

Risk level

Default risk level: medium.

You can change the risk level when you apply this rule.

Compliance evaluation logic

  • If the RAM role does not have administrator permissions or cloud service administrator permissions, the evaluation result is Compliant.

  • If the RAM role has administrator permissions and cloud service administrator permissions, the evaluation result is Non-compliant.

  • If the RAM role is a system role or a service-linked role, the evaluation result is Not Applicable.

Rule details

Item

Description

Rule name

ram-user-role-no-product-admin-access

Rule ID

ram-user-role-no-product-admin-access

Tag

RAM and Role

Automatic remediation

Not supported

Trigger type

Periodic execution

Evaluation frequency

Every 24 hours

Supported resource type

RAM role

Input parameter

None

Non-compliance remediation

Remove administrator and cloud service administrator permissions from the RAM role. Modify the document and description of a custom policy.