Delete idle RAM users

Updated at:

An idle Resource Access Management (RAM) user is a RAM user for which console access is enabled but is never used to log on to the Alibaba Cloud Management Console or a RAM user that has not been used to log on to the Alibaba Cloud Management Console for more than 90 days. We recommend that you delete idle RAM users on a regular basis.

Potential risks

When you enable console access for a RAM user, you set a logon password. The longer a password exists, the higher its risk of exposure. If the password is leaked, an attacker can log on to the Alibaba Cloud Management Console and pose a security risk.

Risk level

Medium-level risks may occur.

Best practices

We recommend that you use single sign-on (SSO) for individuals to reduce the risk of identity exposure.

If SSO cannot be implemented, we recommend that you check the status of RAM users for which console access is enabled and delete idle RAM users on a regular basis.

Governance suggestions

  • For idle RAM users that do not need to log on to the console, disable console access.

    For more information, see Modify console logon settings for a RAM user.

  • If an idle RAM user has no AccessKey, is confirmed to be unused, and is not used as a specific identity in any cloud service, delete the user after its console access has been disabled for a period, such as three months. Before you delete the user, check for its use in the following scenarios:

    • An account used to pull images in Container Registry (ACR).

    • An account used for specific computing tasks in DataWorks.

    • Other Platform as a Service (PaaS) or Software as a Service (SaaS) products, such as Apsara Devops, Cloud Call Center, Enterprise Distributed Application Service (EDAS), or Data Management (DMS).

Governance difficulty

The governance difficulty is low.