AccessKey pair restrictive protection

更新时间:
复制 MD 格式

An AccessKey pair (AK) is the credential used for authentication when you call Alibaba Cloud API operations. Security incidents have shown that after an AK is compromised, attackers can quickly take over the associated account, disrupting your cloud workloads and causing excessive charges or data breaches. To protect your cloud assets, Alibaba Cloud applies restrictive protection to an AK when signs of compromise are detected, preventing further damage.

Symptoms of AK restrictive protection

When you access Alibaba Cloud through direct API calls or developer tools such as CLI, SDK, or Terraform, the following error message indicates that the AK used for authentication is under restrictive protection:

Forbidden : There is a risk of leakage of this AccessKey.

Scope of AK restrictive protection

AK restrictive protection applies to selected high-risk API operations regardless of the source IP address or access method. The list of restricted API operations is subject to change. For the current list, see Restricted API operations.

Remove AK restrictive protection

Because an AK can't be modified after it's created, a compromised AK continues to pose a risk until it's deleted or rotated. For this reason, restrictive protection can't be lifted.

The restricted API list covers a limited set of operations. Attackers can still use a compromised AK to call API operations outside the protection list and affect your cloud workloads. Restrictive protection is therefore a temporary measure. Follow the instructions in AccessKey leak response plan to delete or rotate the AK and remediate the risk.

If you need help during this process or disagree with the restrictive protection measure, go to the Emergency Response page and click Contact Support.

Restricted API operations

Service

API version

API

Description

Resource Access Management (RAM)

2015-05-01

All

N/A

Identity Management Service (IMS)

2019-08-15

All

N/A

CloudSSO

2021-05-15

EnableService

Activate CloudSSO

Elastic Compute Service (ECS)

2014-05-26

RunInstances

Create one or more pay-as-you-go or subscription ECS instances

CreateInstance

Create a subscription or pay-as-you-go ECS instance

CreateAutoProvisioningGroup

Create an auto provisioning group

StartInstance

Start an instance

StartInstances

Start instances

RunCommand

Run a script on instances

DeleteInstance

Delete an ECS instance

DeleteInstances

Delete ECS instances in a batch

DeleteSnapshotGroup

Delete a snapshot group

DeleteSnapshot

Delete a snapshot

DeleteImage

Delete a custom image

CreateCommand

Create a Cloud Assistant command

InvokeCommand

Run a Cloud Assistant command on one or more ECS instances

Elastic Container Instance (ECI)

2018-08-08

CreateContainerGroup

Create a container group

BatchCreateContainerGroups

Create container groups in a batch

DeleteContainerGroup

Delete a container group

DeleteContainerGroups

Delete container groups in a batch

Short Message Service (SMS)

2017-05-25

AddSmsTemplate

Apply for an SMS template

SendSms

Send an SMS message

SendBatchSms

Send SMS messages in a batch

CreateSmsTemplate

Apply for an SMS template

Elastic Desktop Service (EDS)

2020-09-30

StartDesktops

Start cloud desktops

CreateDesktops

Create cloud desktops

CreateDesktopGroup

Create a desktop group

ModifyDesktopGroup

Modify a desktop group

RebootDesktops

Restart cloud desktops

RebuildDesktops

Change the image of cloud desktops

GetConnectionTicket

Connect to a cloud desktop

ModifyDesktopSpec

Modify the specifications of a cloud desktop

RunCommand

Run a remote command on a cloud desktop

Performance Testing Service (PTS)

2019-08-10

StartJMeterTesting

Start a JMeter test

SaveJMeterScene

Save a JMeter scene

CreateJMeterScene

Create a JMeter scene

CreateCronJob

Create a scheduled stress test

StartSceneTesting

Start a stress test

StartDebugging

Start a debugging task

CreateScene

Create a scene

SaveScene

Save a scene

Performance Testing Service (PTS)

2020-10-20

SaveOpenJMeterScene

Save a scene

StartDebuggingJMeterScene

Debug a scene

StartTestingJMeterScene

Run a stress test on a scene

SavePtsScene

Save or modify a scene

CreatePtsScene

Create a scene

StartDebugPtsScene

Debug a scene

StartPtsScene

Start a scene

ApsaraDB RDS for MySQL

2014-08-15

ModifyBackupPolicy

Modify the backup policy of an instance

DeleteBackup

Delete backup files of an instance

DescribeBackups

Query the backup set of an RDS instance

DeleteDBInstance

Release an RDS instance

DestroyDBInstance

Destroy an instance

DeleteDatabase

Delete a database

CreateAccount

Create a database account

ResetAccountPassword

Reset the password of a database account

ResetAccount

Reset the permissions of a privileged account

GrantAccountPrivilege

Grant database access permissions to an account

Database Disaster Recovery (DBS)

2021-01-01

ModifyBackupStrategy

Modify the backup schedule

CreateDownload

Create a download task

DescribeDownloadBackupSetStorageInfo

Query the storage information of a downloadable backup set

Alibaba Cloud DNS

2015-01-09

DeleteDomain

Delete a domain name

AddDomainRecord

Add a DNS record

DeleteDomainRecord

Delete a DNS record

UpdateDomainRecord

Modify a DNS record

SetDomainRecordStatus

Set the status of a DNS record

Alibaba Cloud Billing

2017-12-14

RefundInstance

Unsubscribe from an instance

Instant Computing Service

2023-07-01

CreateJob

Create an E-HPC Instant job

CreatePool

Create a resource pool

Elastic High Performance Computing (E-HPC)

2024-07-30

CreateCluster

Create a cluster

CreateNodes

Create compute nodes in a batch

Data Management (DMS)

2018-11-01

CreateOrder

Create a ticket

CreateDataExportOrder

Create a SQL result set export ticket

CreateDatabaseExportOrder

Create a database export ticket

CreateDataCorrectOrder

Create a regular data change ticket

CreateDataCronClearOrder

Create a historical data cleanup ticket

CreateDataImportOrder

Create a data import ticket

CreateFreeLockCorrectOrder

Create a lock-free change ticket

GetDataExportDownloadURL

Get the download URL of a data export result

GetDbExportDownloadURL

Get the download URL of a database export result

CreateProcCorrectOrder

Create a programmable object change ticket