Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever a single-factor console login is performed. Your alert monitoring rule should query ActionTrail logs for Management Console login attempts to accounts that are not protected by Multi-Factor Authentication (MFA).
Using Simple Log Service (SLS) alerts to detect single-factor Management Console logins can increase visibility into user accounts that are not protected by Multi-Factor Authentication (MFA).
Audit
To dentify if an SLS alert exists and is configured correctly to monitor single-factor console logins in your Alibaba Cloud account, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for detecting single-factor Management Console logins, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.