After you integrate SASE (Secure Access Service Edge) with Resource Directory, you can use an enterprise administrator or a delegated administrator account to add other Alibaba Cloud accounts as member accounts. This allows you to centrally manage cloud assets across multiple member accounts and uniformly control access permissions by using zero trust policies.
Prerequisites
You have activated SASE. For more information, see Getting Started.
Procedure
Before you use the multi-account management feature, enable Resource Directory, add a delegated administrator account, and invite member accounts. Then, add multiple member accounts in SASE for centralized management.
Step 1: Enable Resource Directory
Resource Directory lets you organize Alibaba Cloud accounts into a hierarchy based on your business needs. After you enable Resource Directory, your account becomes the management account with full control over the directory. For more information, see Enable a resource directory.
Step 2: Invite member accounts
You can invite Alibaba Cloud accounts outside your Resource Directory to join as members. After an account accepts the invitation, it becomes a member and can be managed centrally. For more information, see Invite an Alibaba Cloud account to join a resource directory.
Step 3: Add a delegated administrator account
The management account of Resource Directory can designate a member as the delegated administrator account for a trusted service. The delegated administrator account can then access organization and member information and perform business management tasks within that service, separating organization management from day-to-day business operations. For more information, see Manage a delegated administrator account.
Step 4: Manage member accounts
Use the multi-account management feature of SASE to add member accounts from your Resource Directory and centrally manage their access permissions.
Log on to the Secure Access Service Edge console.
-
On the Multi-account Management tab, click Added Member.
-
In the Added Member dialog box, select the desired member accounts and add them to the Selected Member Accounts list on the right.
-
Click OK.
After you add the member accounts, you can view information such as Account UID, Account Name, and Added At in the member account list. You can also perform the following operations:
-
Add remarks
In the Actions column of the member account list, click Remarks for an account to add notes. This helps you distinguish between multiple member accounts.
-
Delete a member account
In the Actions column of the member account list, click Delete for an account to remove it. After a member account is deleted, the current account no longer manages it.
-