Overview of identity and permission administration

更新时间:
复制 MD 格式

Identity and permission administration continuously checks the identities and permissions of your Alibaba Cloud account and its Resource Access Management (RAM) users for security risks. These checks are based on security best practices for cloud migration. This feature helps you promptly identify administrative gaps and provides user-friendly guidance to improve your identity and permission settings.

Enable identity and permission administration

You must enable the identity and permission administration feature to use it. After the feature is enabled, it cannot be disabled.

  1. Log on to the RAM console using your Alibaba Cloud account.

  2. In the left navigation pane, click Overview.

  3. Click the Governance Check tab. In the Governance Check section, click Enable Service.

  4. In the Enable Identity and Permission Administration Service dialog box, you can read and agree to the terms of service, and then click Enable Now.

    After you enable the identity and permission administration feature, the system automatically performs a check. You can also click Re-check to perform a manual check.

    Note

    The administration data is updated approximately every 4 hours. A new report is not generated if you start more than one check within a 4-hour period.

View identity and permission administration data

After the check is complete, you can view the details of pending items.

  1. On the Governance Check tab, view the pending items in the Check Items section.

    You can also click Download Report in the Governance Check section to download and view the check data locally.

  2. Click the target pending item.

    For more information about check items, see Identity and permission administration check items.

  3. On the Check Details page, you can review the check details and the administration plan. Then, go to the corresponding console to perform the administration for the item.

Identity and permission administration check items

Category

Check Item (GovernanceItemType)

Description

Administration Plan

AccessKey management

AccountUnusedAccessKey

Do not use the AccessKey of the Alibaba Cloud account (never used)

Do not use the AccessKey of an Alibaba Cloud account

AccountRecentUsingAccessKey

Do not use the AccessKey of the Alibaba Cloud account (in use within 90 days)

AccountRecentUnusedAccessKey

Do not use the AccessKey of the Alibaba Cloud account (unused for more than 90 days)

UserWithUnrotateAccessKey

Periodically rotate the AccessKeys of RAM users

Periodically rotate the AccessKeys of RAM users

UserWithUnusedAccessKey

No idle AccessKeys for RAM users (never used)

Clean up idle AccessKeys of RAM users

UserWithRecentUnusedAccessKey

No idle AccessKeys for RAM users (unused for more than 90 days)

UserWithTwoUsingAccessKey

A RAM user cannot have two enabled AccessKeys at the same time

A RAM user cannot have two enabled AccessKeys at the same time

RAM user management

UserWithLoginProfileAndAccessKey

Separate human users and programmatic users

Separate console users and programmatic users

UnloginUser

No idle RAM users (never logged on)

Clean up idle RAM users

RecentUnloginUser

No idle RAM users (not logged on for more than 90 days)

RecentAccountLoginTimes

Do not log on with the Alibaba Cloud account

Do not log on with the Alibaba Cloud account

Password and MFA management

AccountBindMfa

Is MFA enabled for your Alibaba Cloud account?

Enable MFA for the Alibaba Cloud account

ConsoleUserWithoutMFAEnabled

Enable MFA for RAM users

Attach an MFA device to a RAM user

StrongPasswordPolicySet

Set strong password strength rules

Set strong password strength rules

Security best practices

SSOLoginEnabled

Use SSO to log on to the console

Scenarios for SSO

Important permission management

AdminPrincipalCnt

Avoid granting admin permissions to too many RAM identities

Avoid granting admin permissions to too many RAM identities

RamRiskPrincipalCnt

Avoid granting important RAM permissions to too many RAM identities

Avoid granting important RAM permissions to too many RAM identities

BssRiskPrincipalCnt

Avoid granting important User Center permissions to too many RAM identities

Avoid granting important Expenses and Costs permissions to too many RAM identities

OssSlsRiskPrincipalCnt

Avoid granting important OSS and SLS permissions to too many RAM identities

Avoid granting important OSS and SLS permissions to too many RAM identities

Fine-grained permission management

CoarseGrainedOssSlsPolicyCnt

Converge access to OSS and SLS

Converge access to OSS and SLS

CoarseGrainedPolicyCnt

Converge the scope of accessible operations

Converge the scope of accessible operations

Authorization efficiency

AdminPolicyAttachmentCnt

The authorization scope for RAM identities with admin permissions is resource groups

Converge the authorization for RAM identities with admin permissions to resource groups

SystemPolicyAttachmentCnt

The authorization scope for RAM identities with service-level system policies is resource groups

Converge the authorization for RAM identities with service-level system policies to resource groups