Ensure that Oracle Cloud Infrastructure (OCI) tenancy administrator users are not configured with API keys in order to minimize the potential attack surface. Identities performing day-to-day operations should never require full tenancy access. Instead, it is recommended to use service-level administrative users with API keys.
Tenancy administrator users have complete access to the organization's OCI tenancy. Using API keys for tenancy administrators poses a significant security risk, as the compromise of these credentials could grant unauthorized control over the entire OCI tenancy.
Audit
To determine if OCI tenancy administrator users are configured with API keys, perform the following operations:
Remediation / Resolution
To remove the API signing keys from your Oracle Cloud Infrastructure (OCI) tenancy administrators, perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Overview of Identity and Access Management
- Managing User Credentials
- Oracle Cloud Infrastructure CLI Documentation
- group list
- user list
- user api-key list
- user api-key delete