All Products
Search
Document Center

Cloud Config:Manage a delegated administrator account

Last Updated:Jun 16, 2026

The management account of a resource directory can designate a member account as the delegated administrator account of Cloud Config. Once configured, the delegated administrator account can manage account groups, view resources of member accounts in each account group, manage compliance packages and rules in each account group, and configure resource data delivery.

Prerequisites

Background information

For more information about delegated administrator accounts, see Manage a delegated administrator account.

Scenarios

A delegated administrator account separates organizational management from auditing, which is essential for cloud security management.

By default, the management account of your resource directory serves as the superuser of your enterprise. As an IT management best practice, we recommend that you keep the management account focused on organizational management of the resource directory rather than resource configuration management. This prevents accidental operations by an account with excessive permissions. Instead, delegate a member account to handle global resource management. For example, you can designate a member account as the delegated administrator account of Cloud Config so that the audit department of your enterprise can own and use the delegated administrator account to evaluate resource compliance and deliver resource data.

Add a delegated administrator account

You can designate a member account in the resource directory as the delegated administrator account of Cloud Config to evaluate monitored resources. The management account shares its Cloud Config permissions with the delegated administrator account, allowing the delegated administrator to manage account groups, view member account resources in account groups, manage compliance packages and rules in account groups, and deliver resource data.

You can use the management account of your resource directory to add a delegated administrator account in the Resource Management console. For more information, see Add a delegated administrator account.

Note

You can add only one delegated administrator account for Cloud Config.

Change the delegated administrator account

We recommend that you do not change the delegated administrator account after it is configured. If a change is necessary, you must first remove the current delegated administrator account and then designate a new one.

  1. Log on to the Resource Management console and remove the original delegated administrator account of Cloud Config by using the management account.

    For more information, see Remove a delegated administrator account.

    Note

    This operation only revokes the permissions shared by the management account from the original delegated administrator account. The existing configurations of that account are retained.

  2. In the Resource Management console, specify a new delegated administrator account.

    For more information, see Add a delegated administrator account.

    Note

    The new delegated administrator account inherits all the permissions of the previous one.

  3. In the Cloud Config console, an employee can use the new delegated administrator account to manage account groups, view resources of member accounts in account groups, manage compliance packages and rules in account groups, and deliver resource data.

    • For more information about how to manage account groups, see Overview.

    • For more information about how to configure the delivery settings of resource data, see Overview.