An AccessKey pair (AK) is the credential used for authentication when you call Alibaba Cloud API operations. Security incidents have shown that after an AK is compromised, attackers can quickly take over the associated account, disrupting your cloud workloads and causing excessive charges or data breaches. To protect your cloud assets, Alibaba Cloud applies restrictive protection to an AK when signs of compromise are detected, preventing further damage.
Symptoms of AK restrictive protection
When you access Alibaba Cloud through direct API calls or developer tools such as CLI, SDK, or Terraform, the following error message indicates that the AK used for authentication is under restrictive protection:
Forbidden : There is a risk of leakage of this AccessKey.
Scope of AK restrictive protection
AK restrictive protection applies to selected high-risk API operations regardless of the source IP address or access method. The list of restricted API operations is subject to change. For the current list, see Restricted API operations.
Remove AK restrictive protection
Because an AK can't be modified after it's created, a compromised AK continues to pose a risk until it's deleted or rotated. For this reason, restrictive protection can't be lifted.
The restricted API list covers a limited set of operations. Attackers can still use a compromised AK to call API operations outside the protection list and affect your cloud workloads. Restrictive protection is therefore a temporary measure. Follow the instructions in AccessKey leak response plan to delete or rotate the AK and remediate the risk.
If you need help during this process or disagree with the restrictive protection measure, go to the Emergency Response page and click Contact Support.
Restricted API operations
|
Service |
API version |
API |
Description |
|
Resource Access Management (RAM) |
2015-05-01 |
All |
N/A |
|
Identity Management Service (IMS) |
2019-08-15 |
All |
N/A |
|
CloudSSO |
2021-05-15 |
EnableService |
Activate CloudSSO |
|
Elastic Compute Service (ECS) |
2014-05-26 |
RunInstances |
Create one or more pay-as-you-go or subscription ECS instances |
|
CreateInstance |
Create a subscription or pay-as-you-go ECS instance |
||
|
CreateAutoProvisioningGroup |
Create an auto provisioning group |
||
|
StartInstance |
Start an instance |
||
|
StartInstances |
Start instances |
||
|
RunCommand |
Run a script on instances |
||
|
DeleteInstance |
Delete an ECS instance |
||
|
DeleteInstances |
Delete ECS instances in a batch |
||
|
DeleteSnapshotGroup |
Delete a snapshot group |
||
|
DeleteSnapshot |
Delete a snapshot |
||
|
DeleteImage |
Delete a custom image |
||
|
CreateCommand |
Create a Cloud Assistant command |
||
|
InvokeCommand |
Run a Cloud Assistant command on one or more ECS instances |
||
|
Elastic Container Instance (ECI) |
2018-08-08 |
CreateContainerGroup |
Create a container group |
|
BatchCreateContainerGroups |
Create container groups in a batch |
||
|
DeleteContainerGroup |
Delete a container group |
||
|
DeleteContainerGroups |
Delete container groups in a batch |
||
|
Short Message Service (SMS) |
2017-05-25 |
AddSmsTemplate |
Apply for an SMS template |
|
SendSms |
Send an SMS message |
||
|
SendBatchSms |
Send SMS messages in a batch |
||
|
CreateSmsTemplate |
Apply for an SMS template |
||
|
Elastic Desktop Service (EDS) |
2020-09-30 |
StartDesktops |
Start cloud desktops |
|
CreateDesktops |
Create cloud desktops |
||
|
CreateDesktopGroup |
Create a desktop group |
||
|
ModifyDesktopGroup |
Modify a desktop group |
||
|
RebootDesktops |
Restart cloud desktops |
||
|
RebuildDesktops |
Change the image of cloud desktops |
||
|
GetConnectionTicket |
Connect to a cloud desktop |
||
|
ModifyDesktopSpec |
Modify the specifications of a cloud desktop |
||
|
RunCommand |
Run a remote command on a cloud desktop |
||
|
Performance Testing Service (PTS) |
2019-08-10 |
StartJMeterTesting |
Start a JMeter test |
|
SaveJMeterScene |
Save a JMeter scene |
||
|
CreateJMeterScene |
Create a JMeter scene |
||
|
CreateCronJob |
Create a scheduled stress test |
||
|
StartSceneTesting |
Start a stress test |
||
|
StartDebugging |
Start a debugging task |
||
|
CreateScene |
Create a scene |
||
|
SaveScene |
Save a scene |
||
|
Performance Testing Service (PTS) |
2020-10-20 |
SaveOpenJMeterScene |
Save a scene |
|
StartDebuggingJMeterScene |
Debug a scene |
||
|
StartTestingJMeterScene |
Run a stress test on a scene |
||
|
SavePtsScene |
Save or modify a scene |
||
|
CreatePtsScene |
Create a scene |
||
|
StartDebugPtsScene |
Debug a scene |
||
|
StartPtsScene |
Start a scene |
||
|
ApsaraDB RDS for MySQL |
2014-08-15 |
ModifyBackupPolicy |
Modify the backup policy of an instance |
|
DeleteBackup |
Delete backup files of an instance |
||
|
DescribeBackups |
Query the backup set of an RDS instance |
||
|
DeleteDBInstance |
Release an RDS instance |
||
|
DestroyDBInstance |
Destroy an instance |
||
|
DeleteDatabase |
Delete a database |
||
|
CreateAccount |
Create a database account |
||
|
ResetAccountPassword |
Reset the password of a database account |
||
|
ResetAccount |
Reset the permissions of a privileged account |
||
|
GrantAccountPrivilege |
Grant database access permissions to an account |
||
|
Database Disaster Recovery (DBS) |
2021-01-01 |
ModifyBackupStrategy |
Modify the backup schedule |
|
CreateDownload |
Create a download task |
||
|
DescribeDownloadBackupSetStorageInfo |
Query the storage information of a downloadable backup set |
||
|
Alibaba Cloud DNS |
2015-01-09 |
DeleteDomain |
Delete a domain name |
|
AddDomainRecord |
Add a DNS record |
||
|
DeleteDomainRecord |
Delete a DNS record |
||
|
UpdateDomainRecord |
Modify a DNS record |
||
|
SetDomainRecordStatus |
Set the status of a DNS record |
||
|
Alibaba Cloud Billing |
2017-12-14 |
RefundInstance |
Unsubscribe from an instance |
|
Instant Computing Service |
2023-07-01 |
CreateJob |
Create an E-HPC Instant job |
|
CreatePool |
Create a resource pool |
||
|
Elastic High Performance Computing (E-HPC) |
2024-07-30 |
CreateCluster |
Create a cluster |
|
CreateNodes |
Create compute nodes in a batch |
||
|
Data Management (DMS) |
2018-11-01 |
CreateOrder |
Create a ticket |
|
CreateDataExportOrder |
Create a SQL result set export ticket |
||
|
CreateDatabaseExportOrder |
Create a database export ticket |
||
|
CreateDataCorrectOrder |
Create a regular data change ticket |
||
|
CreateDataCronClearOrder |
Create a historical data cleanup ticket |
||
|
CreateDataImportOrder |
Create a data import ticket |
||
|
CreateFreeLockCorrectOrder |
Create a lock-free change ticket |
||
|
GetDataExportDownloadURL |
Get the download URL of a data export result |
||
|
GetDbExportDownloadURL |
Get the download URL of a database export result |
||
|
CreateProcCorrectOrder |
Create a programmable object change ticket |