Ensure that your Resource Access Management (RAM) users are using a password policy that requires at least one uppercase letter in order to enforce creating strong user passwords.
Enforcing RAM user passwords strength, pattern, and rotation is vital when it comes to maintaining the security of your Alibaba Cloud account. Having a strong password policy in use will significantly reduce the risk of password-guessing methods and brute-force attacks. The default RAM password policy does not enforce any element in a user password.
Audit
To determine if your password policy enforces at least one uppercase letter for RAM user passwords, perform the following operations:
Remediation / Resolution
To enforce at least one uppercase letter for your RAM user passwords, perform the following operations:
References
- Alibaba Cloud Documentation
- Overview of security settings
- Configure a password policy for RAM users
- Alibaba Cloud CLI Documentation
- GetPasswordPolicy
- SetPasswordPolicy