Operation protection for RAM users

更新时间:
复制 MD 格式

After a Resource Access Management (RAM) user binds a multi-factor authentication (MFA) device, the console requires secondary authentication for critical operations, such as creating an AccessKey pair or deleting an instance. This requirement enhances account security.

Background information

Operation protection for RAM users requires secondary authentication for critical console operations, such as creating an AccessKey pair or deleting an instance. This verification helps prevent business losses that result from accidental or malicious actions and improves account security.

  • Operation protection for an Alibaba Cloud account is enabled by default and cannot be disabled. You can only change the protection level and authentication method. For more information, see Set operation protection for your account.

  • Operation protection for a RAM user depends on whether an MFA device is bound. It cannot be disabled independently, and you cannot change the default protection level.

Procedure

  • Enable operation protection for a RAM user: Bind an MFA device. After you bind a device, verification is required for sensitive operations in the console. For more information, see Bind an MFA device to a RAM user.

  • Disable operation protection for a RAM user: Unbind all MFA devices. After all devices are unbound, verification is no longer required for sensitive operations. For more information, see Unbind an MFA device from a RAM user.

List of supported critical operations

The following table lists some common high-risk critical operations in the console.

Product category

Cloud product

Console operation description

Security

Resource Access Management (RAM)

  • Create an AccessKey pair for an Alibaba Cloud account or a RAM user

  • Create a role

  • Create an access policy

  • Change the status of an AccessKey pair

  • Delete an AccessKey pair of an Alibaba Cloud account or a RAM user

  • Delete a RAM user

Compute

Elastic Compute Service (ECS)

  • Delete a custom image

  • Delete an instance

  • Modify instance properties

  • Delete a snapshot

Compute

Simple Application Server (SWAS)

  • Reset a simple application server

  • Restart instances in a batch

  • Modify some instance information

Compute

Edge Node Service (ENS)

  • Restart an instance

  • Stop an instance

  • Modify instance properties

Container

Container Registry (ACR)

  • Delete an image repository namespace

  • Delete an instance

Storage

File Storage (NAS)

  • Run an uninstall command

  • Delete an existing mount target

  • Delete an existing file system

Network and CDN

Content Delivery Network (CDN)

  • Disable a domain name

  • Delete a domain name

Network and CDN

Server Load Balancer (SLB)

  • Delete an SLB instance

Middleware

Microservices Engine (MSE)

  • Delete a gateway service source

  • Detach an SLB instance from a gateway

  • Delete a cluster

  • Delete gateway information

  • Delete a domain name associated with a gateway

Database

ApsaraDB RDS

  • Delete an instance

  • Delete a database

  • Delete a database account

  • Restart an RDS instance

  • Reset the password of a database account

Database

Cloud-native database PolarDB

  • Delete a backup of a PolarDB cluster

  • Reset the password of a PolarDB database account

  • Delete a database in a PolarDB cluster

  • Delete a database account

  • Release a pay-as-you-go PolarDB cluster