Change the logon password of your Alibaba Cloud account while you are logged on to enhance account security.
Before you begin
This topic applies only to changing the logon password of your Alibaba Cloud account while you are logged on. Users who log on as a RAM user or RAM role, or through enterprise SSO, cannot change the password of the Alibaba Cloud account. Contact the account administrator to log on to the Alibaba Cloud account and change the password.
This topic covers only the logon password of the Alibaba Cloud Management Console. Server passwords (ECS instance logon password, Simple Application Server password) are completely separate from the account logon password and are not interchangeable. For the differences between these password types and how to change a server password, see What is the difference between the Alibaba Cloud account password and the ECS or server password?.
Is your current password still valid?
If you forgot your password and cannot log on, see Forgot password.
If your current password is valid and you can log on, follow the procedure in this topic.
Change the password of an account other than your Alibaba Cloud account
To change the password of a Resource Access Management (RAM) user, contact the administrator of the Alibaba Cloud account or a RAM administrator to change the password in the RAM console. For more information, see Change the password of a RAM user.
To change the logon password of an enterprise SSO user, change the password at your enterprise identity provider (IdP).
Procedure
Log on to the Alibaba Cloud Account Center, go to the Security Settings page, and in the Basic Settings section, click Modify next to Logon Password.
You can also go to the Overview page, and in the My Account section, click the
icon next to Logon Password to change the password.On the Verify Identity page, verify your identity by using your existing secure phone number, logon email, or time-based one-time password (TOTP). If you cannot complete the identity verification, submit an appeal to change your phone number or email address. For more information, see the appeal process.
After the verification succeeds, the Change Password page appears. Enter a new logon password and click OK.
After the password is changed, remember your new logon password and click Re-logon to log on to the Alibaba Cloud website again.
What to do next
After the password is changed, your Alibaba Cloud account is immediately logged out from all devices.
Log on again by using the new password on the Alibaba Cloud Management Console or the Alibaba Cloud app.
To protect your account, when you log on from an unfamiliar device or network environment by using the new password, the system may require secondary authentication such as SMS verification.
To further protect your account, complete the following tasks after you change the logon password:
Rotate AccessKey pairs (API keys): If you suspect that your account credentials have been compromised, immediately disable or delete old AccessKey pairs and create new ones. This prevents attackers from using leaked keys to continue accessing your cloud resources.
Review RAM users and access permissions: Check the RAM user list and access policies. Remove unauthorized RAM users, abnormal access policies, or expired temporary authorizations to prevent attackers from maintaining access permissions through backdoors.
FAQ
My secure phone number or email address is no longer in use during identity verification. What do I do?
If you cannot complete the identity verification, submit an appeal to change your password. For more information, see the appeal process.
I cannot receive SMS or email verification codes. What do I do?
Troubleshoot the issue by using the following steps:
SMS verification code: Check whether your phone has overdue charges, whether the signal is normal, and whether you have installed any call or message blocking software or added the carrier number to a blocklist.
Email verification code: Check whether the email was classified as spam or placed in a subscription email folder.
If you have not received the code for an extended period due to network latency, wait or retry later. If the issue persists, contact technical support.
Why can I still log on with my old password after changing it?
This is usually caused by browser cache or autofill, not a failed password change. Try the following:
Clear your browser cache and saved password entries.
Open the logon page in incognito or private browsing mode.
Manually enter the new password instead of relying on browser autofill.
If the issue persists after you rule out cache problems, use the Forgot password process to reset your password.
Will other devices be logged out after I change my password?
Yes. After you change the logon password, your Alibaba Cloud account is immediately logged out from all logged-on devices and sessions, including PCs and mobile apps. To log on again by using the new password, see What to do next.
If you suspect unauthorized access, changing your password is an effective way to stop all abnormal sessions.
Review recent logon records through ActionTrail to check for suspicious logon IPs.
Can I disable password logon and only use SMS verification codes or passkeys to log on?
No. The logon password is the basic verification method for Alibaba Cloud accounts. Even if you have enabled multi-factor authentication (MFA), bound a secure phone number, or set up a passkey, the password logon entry is always available and cannot be disabled.
To enhance your account security, use the following methods instead of disabling password logon:
Enable multi-factor authentication (MFA). For instructions, see Enable MFA.
Set a strong password and change it periodically.
Bind a secure phone number for secondary authentication on unusual logons.
What is the difference between the Alibaba Cloud account password and the ECS or server password?
The two types of passwords are completely separate and cannot be used interchangeably:
| Type | Purpose | How to change |
| Alibaba Cloud account logon password | Log on to the Alibaba Cloud Management Console (this topic) | Account Center > Security Settings |
| ECS instance password | Remote connection to a cloud server by using Secure Shell (SSH) or RDP | ECS console > Instance Details |
| Simple Application Server password | Remote connection to simple application servers | Simple Application Server console |
To change a server password, go to the corresponding product console. See Change the logon password of an ECS instance or Change the password of a Simple Application Server.
How do I change my account logon name?
The logon name is a configuration item that is independent of the logon password. The entry point for changing the logon name is also on the Account Center > Overview or Security Settings page. The logon name is auto-generated during registration and can be changed to a name that is easier to remember (Chinese, English, and digits are supported). For more information, see Change the logon name.