Multi-account management

更新时间:
复制 MD 格式

After you integrate SASE (Secure Access Service Edge) with Resource Directory, you can use an enterprise administrator or a delegated administrator account to add other Alibaba Cloud accounts as member accounts. This allows you to centrally manage cloud assets across multiple member accounts and uniformly control access permissions by using zero trust policies.

Prerequisites

You have activated SASE. For more information, see Getting Started.

Procedure

Before you use the multi-account management feature, enable Resource Directory, add a delegated administrator account, and invite member accounts. Then, add multiple member accounts in SASE for centralized management.

Step 1: Enable Resource Directory

Resource Directory lets you organize Alibaba Cloud accounts into a hierarchy based on your business needs. After you enable Resource Directory, your account becomes the management account with full control over the directory. For more information, see Enable a resource directory.

Step 2: Invite member accounts

You can invite Alibaba Cloud accounts outside your Resource Directory to join as members. After an account accepts the invitation, it becomes a member and can be managed centrally. For more information, see Invite an Alibaba Cloud account to join a resource directory.

Step 3: Add a delegated administrator account

The management account of Resource Directory can designate a member as the delegated administrator account for a trusted service. The delegated administrator account can then access organization and member information and perform business management tasks within that service, separating organization management from day-to-day business operations. For more information, see Manage a delegated administrator account.

Step 4: Manage member accounts

Use the multi-account management feature of SASE to add member accounts from your Resource Directory and centrally manage their access permissions.

  1. Log on to the Secure Access Service Edge console.

  2. On the Multi-account Management tab, click Added Member.

  3. In the Added Member dialog box, select the desired member accounts and add them to the Selected Member Accounts list on the right.

  4. Click OK.

    After you add the member accounts, you can view information such as Account UID, Account Name, and Added At in the member account list. You can also perform the following operations:

    • Add remarks

      In the Actions column of the member account list, click Remarks for an account to add notes. This helps you distinguish between multiple member accounts.

    • Delete a member account

      In the Actions column of the member account list, click Delete for an account to remove it. After a member account is deleted, the current account no longer manages it.