AccessKey pair restrictive protection
An AccessKey pair (AK) is the credential used for authentication when you call Alibaba Cloud API operations. Security incidents have shown that after an AK is compromised, attackers can quickly take over the associated account, disrupting your cloud workloads and causing excessive charges or data breaches. To protect your cloud assets, Alibaba Cloud applies restrictive protection to an AK when signs of compromise are detected, preventing further damage.
Symptoms of AK restrictive protection
When you access Alibaba Cloud through direct API calls or developer tools such as CLI, SDK, or Terraform, the following error message indicates that the AK used for authentication is under restrictive protection:
Forbidden : There is a risk of leakage of this AccessKey.
Scope of AK restrictive protection
AK restrictive protection applies to selected high-risk API operations regardless of the source IP address or access method. The list of restricted API operations is subject to change. For the current list, see Restricted API operations.
Remove AK restrictive protection
Because an AK can't be modified after it's created, a compromised AK continues to pose a risk until it's deleted or rotated. For this reason, restrictive protection can't be lifted.
The restricted API list covers a limited set of operations. Attackers can still use a compromised AK to call API operations outside the protection list and affect your cloud workloads. Restrictive protection is therefore a temporary measure. Follow the instructions in AccessKey leak response plan to delete or rotate the AK and remediate the risk.
If you need help during this process or disagree with the restrictive protection measure, go to the Emergency Response page and click Contact Support.
How to avoid triggering restrictive protection
After you create an AccessKey (AK) pair, configure a network access restriction policy to limit the sources of API calls to trusted IP addresses.
Configure a network access restriction policy
-
On the user details page in the RAM console, click the Credentials tab.
-
In the AccessKey pair section, click Network Access Restriction Policy in the Actions column of the target AK.
-
Turn on the policy, add a public access policy, and enter the trusted source IP addresses.
-
Enter the AccessKey ID to confirm the change, and then submit.
If you do not configure a public access policy or a VPC access policy, all access of the corresponding network type is blocked by default.
Network access restriction policies have two types: a public access policy, which restricts the source IP addresses, and a VPC access policy, which restricts both the VPC and the source IP addresses.
Rotate an AccessKey pair
-
On the Credentials tab, click Create AccessKey.
-
Select a usage scenario and complete MFA verification to create a new AccessKey pair.
-
Update your applications to use the new AccessKey pair. After you confirm that your business runs as expected, disable and delete the old AccessKey pair.
For detailed steps, see Rotate the AccessKey pair of a RAM user.
Restricted API operations
|
Service |
API version |
API |
Description |
|
Resource Access Management (RAM) |
2015-05-01 |
All |
N/A |
|
Identity Management Service (IMS) |
2019-08-15 |
All |
N/A |
|
CloudSSO |
2021-05-15 |
EnableService |
Activate CloudSSO |
|
Elastic Compute Service (ECS) |
2014-05-26 |
RunInstances |
Create one or more pay-as-you-go or subscription ECS instances |
|
CreateInstance |
Create a subscription or pay-as-you-go ECS instance |
||
|
CreateAutoProvisioningGroup |
Create an auto provisioning group |
||
|
StartInstance |
Start an instance |
||
|
StartInstances |
Start instances |
||
|
RunCommand |
Run a script on instances |
||
|
DeleteInstance |
Delete an ECS instance |
||
|
DeleteInstances |
Delete ECS instances in a batch |
||
|
DeleteSnapshotGroup |
Delete a snapshot group |
||
|
DeleteSnapshot |
Delete a snapshot |
||
|
DeleteImage |
Delete a custom image |
||
|
CreateCommand |
Create a Cloud Assistant command |
||
|
InvokeCommand |
Run a Cloud Assistant command on one or more ECS instances |
||
|
Elastic Container Instance (ECI) |
2018-08-08 |
CreateContainerGroup |
Create a container group |
|
BatchCreateContainerGroups |
Create container groups in a batch |
||
|
DeleteContainerGroup |
Delete a container group |
||
|
DeleteContainerGroups |
Delete container groups in a batch |
||
|
Short Message Service (SMS) |
2017-05-25 |
AddSmsTemplate |
Apply for an SMS template |
|
SendSms |
Send an SMS message |
||
|
SendBatchSms |
Send SMS messages in a batch |
||
|
CreateSmsTemplate |
Apply for an SMS template |
||
|
Elastic Desktop Service (EDS) |
2020-09-30 |
StartDesktops |
Start cloud desktops |
|
CreateDesktops |
Create cloud desktops |
||
|
CreateDesktopGroup |
Create a desktop group |
||
|
ModifyDesktopGroup |
Modify a desktop group |
||
|
RebootDesktops |
Restart cloud desktops |
||
|
RebuildDesktops |
Change the image of cloud desktops |
||
|
GetConnectionTicket |
Connect to a cloud desktop |
||
|
ModifyDesktopSpec |
Modify the specifications of a cloud desktop |
||
|
RunCommand |
Run a remote command on a cloud desktop |
||
|
Performance Testing Service (PTS) |
2019-08-10 |
StartJMeterTesting |
Start a JMeter test |
|
SaveJMeterScene |
Save a JMeter scene |
||
|
CreateJMeterScene |
Create a JMeter scene |
||
|
CreateCronJob |
Create a scheduled stress test |
||
|
StartSceneTesting |
Start a stress test |
||
|
StartDebugging |
Start a debugging task |
||
|
CreateScene |
Create a scene |
||
|
SaveScene |
Save a scene |
||
|
Performance Testing Service (PTS) |
2020-10-20 |
SaveOpenJMeterScene |
Save a scene |
|
StartDebuggingJMeterScene |
Debug a scene |
||
|
StartTestingJMeterScene |
Run a stress test on a scene |
||
|
SavePtsScene |
Save or modify a scene |
||
|
CreatePtsScene |
Create a scene |
||
|
StartDebugPtsScene |
Debug a scene |
||
|
StartPtsScene |
Start a scene |
||
|
ApsaraDB RDS for MySQL |
2014-08-15 |
ModifyBackupPolicy |
Modify the backup policy of an instance |
|
DeleteBackup |
Delete backup files of an instance |
||
|
DescribeBackups |
Query the backup set of an RDS instance |
||
|
DeleteDBInstance |
Release an RDS instance |
||
|
DestroyDBInstance |
Destroy an instance |
||
|
DeleteDatabase |
Delete a database |
||
|
CreateAccount |
Create a database account |
||
|
ResetAccountPassword |
Reset the password of a database account |
||
|
ResetAccount |
Reset the permissions of a privileged account |
||
|
GrantAccountPrivilege |
Grant database access permissions to an account |
||
|
Database Disaster Recovery (DBS) |
2021-01-01 |
ModifyBackupStrategy |
Modify the backup schedule |
|
CreateDownload |
Create a download task |
||
|
DescribeDownloadBackupSetStorageInfo |
Query the storage information of a downloadable backup set |
||
|
Alibaba Cloud DNS |
2015-01-09 |
DeleteDomain |
Delete a domain name |
|
AddDomainRecord |
Add a DNS record |
||
|
DeleteDomainRecord |
Delete a DNS record |
||
|
UpdateDomainRecord |
Modify a DNS record |
||
|
SetDomainRecordStatus |
Set the status of a DNS record |
||
|
Alibaba Cloud Billing |
2017-12-14 |
RefundInstance |
Unsubscribe from an instance |
|
Instant Computing Service |
2023-07-01 |
CreateJob |
Create an E-HPC Instant job |
|
CreatePool |
Create a resource pool |
||
|
Elastic High Performance Computing (E-HPC) |
2024-07-30 |
CreateCluster |
Create a cluster |
|
CreateNodes |
Create compute nodes in a batch |
||
|
Data Management (DMS) |
2018-11-01 |
CreateOrder |
Create a ticket |
|
CreateDataExportOrder |
Create a SQL result set export ticket |
||
|
CreateDatabaseExportOrder |
Create a database export ticket |
||
|
CreateDataCorrectOrder |
Create a regular data change ticket |
||
|
CreateDataCronClearOrder |
Create a historical data cleanup ticket |
||
|
CreateDataImportOrder |
Create a data import ticket |
||
|
CreateFreeLockCorrectOrder |
Create a lock-free change ticket |
||
|
GetDataExportDownloadURL |
Get the download URL of a data export result |
||
|
GetDbExportDownloadURL |
Get the download URL of a database export result |
||
|
CreateProcCorrectOrder |
Create a programmable object change ticket |