After a Resource Access Management (RAM) user binds a multi-factor authentication (MFA) device, the console requires secondary authentication for critical operations, such as creating an AccessKey pair or deleting an instance. This requirement enhances account security.
Background information
Operation protection for RAM users requires secondary authentication for critical console operations, such as creating an AccessKey pair or deleting an instance. This verification helps prevent business losses that result from accidental or malicious actions and improves account security.
Operation protection for an Alibaba Cloud account is enabled by default and cannot be disabled. You can only change the protection level and authentication method. For more information, see Set operation protection for your account.
Operation protection for a RAM user depends on whether an MFA device is bound. It cannot be disabled independently, and you cannot change the default protection level.
Procedure
Enable operation protection for a RAM user: Bind an MFA device. After you bind a device, verification is required for sensitive operations in the console. For more information, see Bind an MFA device to a RAM user.
Disable operation protection for a RAM user: Unbind all MFA devices. After all devices are unbound, verification is no longer required for sensitive operations. For more information, see Unbind an MFA device from a RAM user.
List of supported critical operations
The following table lists some common high-risk critical operations in the console.
Product category | Cloud product | Console operation description |
Security | Resource Access Management (RAM) |
|
Compute | Elastic Compute Service (ECS) |
|
Compute | Simple Application Server (SWAS) |
|
Compute | Edge Node Service (ENS) |
|
Container | Container Registry (ACR) |
|
Storage | File Storage (NAS) |
|
Network and CDN | Content Delivery Network (CDN) |
|
Network and CDN | Server Load Balancer (SLB) |
|
Middleware | Microservices Engine (MSE) |
|
Database | ApsaraDB RDS |
|
Database | Cloud-native database PolarDB |
|