Multi-factor authentication (MFA)
Multi-factor authentication (MFA) adds a second verification factor beyond the logon name and password of a Resource Access Management (RAM) user. RAM supports passkeys, virtual MFA devices, secure phones, and security email addresses as MFA methods. This topic describes how to select an MFA method and the usage notes and limits that apply.
To protect your account and assets, Alibaba Cloud has been enabling mandatory MFA at logon for all RAM users since August 20, 2024. For more information, see the announcement.
All MFA methods described in this topic apply to RAM users. For information about the MFA methods and procedures for an Alibaba Cloud account, see Step 3: Configure MFA for your account.
Why configure MFA for RAM users?
MFA is one of the best practices for improving account security. It adds an extra layer of protection beyond the logon name and password of a RAM user.
The key benefits of enabling MFA are:
Secure account logon: Even if your password is compromised, an attacker who does not hold your MFA device, such as your mobile phone, cannot log on to the Alibaba Cloud Management Console as the RAM user.
Protection for sensitive operations: After you bind an MFA device to a RAM user, MFA provides secondary identity verification for the sensitive operations that the RAM user performs in the Alibaba Cloud Management Console.
How MFA works
After you enable MFA, you must complete the following two verification steps to log on to Alibaba Cloud:
First factor: Enter the logon name and password of the RAM user.
Second factor: Complete another verification step, such as entering the 6-digit verification code that a virtual MFA device generates.
A passkey completes both verification steps at once. For more information, see Manage passkeys for RAM users.
MFA and permission grants
Comparison of MFA methods for RAM users
You can select one or more MFA methods for a RAM user based on your business requirements and the security level that you need. The following table compares the supported methods. A passkey provides the highest security level, and a virtual MFA device is the recommended primary method because it has no region or carrier restrictions.
MFA method | Verification method | Verification scenarios | Security level | Requirements and limits | Recommended use |
Passkey | Biometrics (fingerprint or facial recognition) or a device PIN. A passkey verifies that the authentication device is legitimate and uses the biometric capabilities built into the device. | Secondary identity verification for console logon and sensitive operations | Highest | A compatible device (computer or mobile phone) and browser. For more information, see What is a passkey?. | Scenarios that require the highest security level and convenient passwordless logon |
Virtual MFA device | Time-based one-time password (TOTP) | Secondary identity verification for console logon and sensitive operations | High | An authenticator app on a smartphone, such as the Alibaba Cloud app or Google Authenticator | (Recommended) The primary MFA method. No region or carrier restrictions apply. |
Secure phone | SMS verification code | Secondary identity verification for console logon and sensitive operations | Medium | A mobile phone and carrier signal. A secure phone number can be bound to a maximum of five RAM users. | A convenient backup for a passkey or a virtual MFA device |
Security email address | Email verification code | Secondary identity verification for sensitive operations. Not supported for logon verification. | Medium | An email service. A security email address can be bound to a maximum of five RAM users. | A backup method for operation verification when the primary MFA device is unavailable |
(Recommended) Configure at least two different MFA methods for each RAM user, such as a passkey and a secure phone. This prevents logon failures caused by a lost or damaged device or an uninstalled app.
Universal 2nd Factor (U2F) devices have been upgraded to passkeys. If you have bound a U2F device, we recommend that you upgrade it to a passkey. For more information, see Upgrade a U2F key to a passkey.
Limits
The following limits apply to the MFA methods that you configure for RAM users:
Virtual MFA devices and secure phones can be used when you log on to Alibaba Cloud from a browser or the Alibaba Cloud app.
For the limits and supported device types of passkeys, see Manage passkeys for RAM users.