Ensure that your Resource Access Management (RAM) users are using a strong password policy that is configured to temporarily block logon after several incorrect logon attempts. Trend Vision One™ - Cloud Posture provides you with the capability to define the maximum number of login attempts (between 1 and 32), upon enabling this Trend Vision One™ - Cloud Posture rule.
Enforcing RAM user passwords strength, pattern, and rotation is vital when it comes to maintaining the security of your Alibaba Cloud account. Having a strong password policy in use will significantly reduce the risk of password-guessing methods and brute-force attacks.
Audit
To determine if your password policy is configured to limit the number of login attempts, perform the following operations:
Remediation / Resolution
To ensure that your password policy is configured to limit the number of login attempts, perform the following operations:
References
- Alibaba Cloud Documentation
- Overview of security settings
- Configure a password policy for RAM users
- Alibaba Cloud CLI Documentation
- GetPasswordPolicy
- SetPasswordPolicy