Identity and permission administration continuously checks the identities and permissions of your Alibaba Cloud account and its Resource Access Management (RAM) users for security risks. These checks are based on security best practices for cloud migration. This feature helps you promptly identify administrative gaps and provides user-friendly guidance to improve your identity and permission settings.
Enable identity and permission administration
You must enable the identity and permission administration feature to use it. After the feature is enabled, it cannot be disabled.
Log on to the RAM console using your Alibaba Cloud account.
In the left navigation pane, click Overview.
Click the Governance Check tab. In the Governance Check section, click Enable Service.
In the Enable Identity and Permission Administration Service dialog box, you can read and agree to the terms of service, and then click Enable Now.
After you enable the identity and permission administration feature, the system automatically performs a check. You can also click Re-check to perform a manual check.
NoteThe administration data is updated approximately every 4 hours. A new report is not generated if you start more than one check within a 4-hour period.
View identity and permission administration data
After the check is complete, you can view the details of pending items.
On the Governance Check tab, view the pending items in the Check Items section.
You can also click Download Report in the Governance Check section to download and view the check data locally.
Click the target pending item.
For more information about check items, see Identity and permission administration check items.
On the Check Details page, you can review the check details and the administration plan. Then, go to the corresponding console to perform the administration for the item.
Identity and permission administration check items
Category | Check Item (GovernanceItemType) | Description | Administration Plan |
AccessKey management | AccountUnusedAccessKey | Do not use the AccessKey of the Alibaba Cloud account (never used) | |
AccountRecentUsingAccessKey | Do not use the AccessKey of the Alibaba Cloud account (in use within 90 days) | ||
AccountRecentUnusedAccessKey | Do not use the AccessKey of the Alibaba Cloud account (unused for more than 90 days) | ||
UserWithUnrotateAccessKey | Periodically rotate the AccessKeys of RAM users | ||
UserWithUnusedAccessKey | No idle AccessKeys for RAM users (never used) | ||
UserWithRecentUnusedAccessKey | No idle AccessKeys for RAM users (unused for more than 90 days) | ||
UserWithTwoUsingAccessKey | A RAM user cannot have two enabled AccessKeys at the same time | A RAM user cannot have two enabled AccessKeys at the same time | |
RAM user management | UserWithLoginProfileAndAccessKey | Separate human users and programmatic users | |
UnloginUser | No idle RAM users (never logged on) | ||
RecentUnloginUser | No idle RAM users (not logged on for more than 90 days) | ||
RecentAccountLoginTimes | Do not log on with the Alibaba Cloud account | ||
Password and MFA management | AccountBindMfa | Is MFA enabled for your Alibaba Cloud account? | |
ConsoleUserWithoutMFAEnabled | Enable MFA for RAM users | ||
StrongPasswordPolicySet | Set strong password strength rules | ||
Security best practices | SSOLoginEnabled | Use SSO to log on to the console | |
Important permission management | AdminPrincipalCnt | Avoid granting admin permissions to too many RAM identities | |
RamRiskPrincipalCnt | Avoid granting important RAM permissions to too many RAM identities | Avoid granting important RAM permissions to too many RAM identities | |
BssRiskPrincipalCnt | Avoid granting important User Center permissions to too many RAM identities | Avoid granting important Expenses and Costs permissions to too many RAM identities | |
OssSlsRiskPrincipalCnt | Avoid granting important OSS and SLS permissions to too many RAM identities | Avoid granting important OSS and SLS permissions to too many RAM identities | |
Fine-grained permission management | CoarseGrainedOssSlsPolicyCnt | Converge access to OSS and SLS | |
CoarseGrainedPolicyCnt | Converge the scope of accessible operations | ||
Authorization efficiency | AdminPolicyAttachmentCnt | The authorization scope for RAM identities with admin permissions is resource groups | Converge the authorization for RAM identities with admin permissions to resource groups |
SystemPolicyAttachmentCnt | The authorization scope for RAM identities with service-level system policies is resource groups | Converge the authorization for RAM identities with service-level system policies to resource groups |