To secure your Alibaba Cloud environment and adhere to security best practices, ensure that the Alibaba Cloud root account is not using access keys to perform API requests to access cloud resources or billing information. Trend Vision One™ recommends removing any existing root account key pairs and instead use individual RAM users for accessing resources within your cloud account.
Having access to your root account key pair grants individuals unrestricted access to all your Alibaba Cloud services and resources, including sensitive billing information. Eliminating these credentials from your root account will significantly reduce the likelihood of unauthorized access to your cloud resources.
Audit
To determine the existence of your Alibaba Cloud root account access keys, perform the following operations:
Remediation / Resolution
To remove the access keys created for your Alibaba Cloud root account, perform the following operations:
Deleting the root account access keys via Alibaba Cloud CLI (aliyun) is not currently supported.References
- Alibaba Cloud Documentation
- Use RAM to ensure security of the Alibaba Cloud resources of your enterprise
- Terms
- Generate and download user credential reports
- ossutil Documentation
- GenerateCredentialReport
- GetCredentialReport