Multi-factor authentication (MFA)

Updated at:

Multi-factor authentication (MFA) adds a second verification factor beyond the logon name and password of a Resource Access Management (RAM) user. RAM supports passkeys, virtual MFA devices, secure phones, and security email addresses as MFA methods. This topic describes how to select an MFA method and the usage notes and limits that apply.

  • To protect your account and assets, Alibaba Cloud has been enabling mandatory MFA at logon for all RAM users since August 20, 2024. For more information, see the announcement.

  • All MFA methods described in this topic apply to RAM users. For information about the MFA methods and procedures for an Alibaba Cloud account, see Step 3: Configure MFA for your account.

Why configure MFA for RAM users?

MFA is one of the best practices for improving account security. It adds an extra layer of protection beyond the logon name and password of a RAM user.

The key benefits of enabling MFA are:

  • Secure account logon: Even if your password is compromised, an attacker who does not hold your MFA device, such as your mobile phone, cannot log on to the Alibaba Cloud Management Console as the RAM user.

  • Protection for sensitive operations: After you bind an MFA device to a RAM user, MFA provides secondary identity verification for the sensitive operations that the RAM user performs in the Alibaba Cloud Management Console.

How MFA works

After you enable MFA, you must complete the following two verification steps to log on to Alibaba Cloud:

  1. First factor: Enter the logon name and password of the RAM user.

  2. Second factor: Complete another verification step, such as entering the 6-digit verification code that a virtual MFA device generates.

    A passkey completes both verification steps at once. For more information, see Manage passkeys for RAM users.

MFA and permission grants

MFA is independent of permission grants. Granting permissions to a RAM user, such as granting the AliyunBSSFullAccess system policy for billing management, does not depend on whether MFA is enabled. Decide whether to enable MFA based only on the logon security requirements of the RAM user.

Comparison of MFA methods for RAM users

You can select one or more MFA methods for a RAM user based on your business requirements and the security level that you need. The following table compares the supported methods. A passkey provides the highest security level, and a virtual MFA device is the recommended primary method because it has no region or carrier restrictions.

MFA method

Verification method

Verification scenarios

Security level

Requirements and limits

Recommended use

Passkey

Biometrics (fingerprint or facial recognition) or a device PIN. A passkey verifies that the authentication device is legitimate and uses the biometric capabilities built into the device.

Secondary identity verification for console logon and sensitive operations

Highest

A compatible device (computer or mobile phone) and browser. For more information, see What is a passkey?.

Scenarios that require the highest security level and convenient passwordless logon

Virtual MFA device

Time-based one-time password (TOTP)

Secondary identity verification for console logon and sensitive operations

High

An authenticator app on a smartphone, such as the Alibaba Cloud app or Google Authenticator

(Recommended) The primary MFA method. No region or carrier restrictions apply.

Secure phone

SMS verification code

Secondary identity verification for console logon and sensitive operations

Medium

A mobile phone and carrier signal. A secure phone number can be bound to a maximum of five RAM users.

A convenient backup for a passkey or a virtual MFA device

Security email address

Email verification code

Secondary identity verification for sensitive operations. Not supported for logon verification.

Medium

An email service. A security email address can be bound to a maximum of five RAM users.

A backup method for operation verification when the primary MFA device is unavailable

  • (Recommended) Configure at least two different MFA methods for each RAM user, such as a passkey and a secure phone. This prevents logon failures caused by a lost or damaged device or an uninstalled app.

  • Universal 2nd Factor (U2F) devices have been upgraded to passkeys. If you have bound a U2F device, we recommend that you upgrade it to a passkey. For more information, see Upgrade a U2F key to a passkey.

Limits

The following limits apply to the MFA methods that you configure for RAM users:

  • Virtual MFA devices and secure phones can be used when you log on to Alibaba Cloud from a browser or the Alibaba Cloud app.

  • For the limits and supported device types of passkeys, see Manage passkeys for RAM users.

References

Multi-factor authentication (MFA) FAQ