Identify inactive Resource Access Management (RAM) users that are not designated for API access, and disable their access to Alibaba Cloud console as an additional security measure for protecting your cloud resources against unauthorized access. A RAM user is considered inactive when has not logged on for 90 days or longer.
Disabling console access for your inactive Alibaba Cloud RAM users can reduce the risk of unauthorized access to your cloud services and resources, and help you manage the user-based access more efficiently.
Audit
To identify the RAM users that have not been logged on for 90 days or longer, perform the following operations:
Remediation / Resolution
To disable console access for your inactive Resource Access Management (RAM) users, perform the following operations:
References
- Alibaba Cloud Documentation
- Overview of RAM users
- Manage console logon settings for a RAM user
- Alibaba Cloud CLI Documentation
- ListUsers
- GetUser
- getloginprofile
- DeleteLoginProfile