The management account of a resource directory can designate a member account as the delegated administrator account of Cloud Config. Once configured, the delegated administrator account can manage account groups, view resources of member accounts in each account group, manage compliance packages and rules in each account group, and configure resource data delivery.
Prerequisites
-
A management account is used to log on to the Cloud Config console.
-
Resource Directory is enabled. For more information, see Enable a resource directory.
-
Member accounts are created in your resource directory, or Alibaba Cloud accounts are invited to join the resource directory. For more information, see Create a member and Invite an Alibaba Cloud account to join a resource directory.
Background information
For more information about delegated administrator accounts, see Manage a delegated administrator account.
Scenarios
A delegated administrator account separates organizational management from auditing, which is essential for cloud security management.
By default, the management account of your resource directory serves as the superuser of your enterprise. As an IT management best practice, we recommend that you keep the management account focused on organizational management of the resource directory rather than resource configuration management. This prevents accidental operations by an account with excessive permissions. Instead, delegate a member account to handle global resource management. For example, you can designate a member account as the delegated administrator account of Cloud Config so that the audit department of your enterprise can own and use the delegated administrator account to evaluate resource compliance and deliver resource data.
Add a delegated administrator account
You can designate a member account in the resource directory as the delegated administrator account of Cloud Config to evaluate monitored resources. The management account shares its Cloud Config permissions with the delegated administrator account, allowing the delegated administrator to manage account groups, view member account resources in account groups, manage compliance packages and rules in account groups, and deliver resource data.
You can use the management account of your resource directory to add a delegated administrator account in the Resource Management console. For more information, see Add a delegated administrator account.
You can add only one delegated administrator account for Cloud Config.
Change the delegated administrator account
We recommend that you do not change the delegated administrator account after it is configured. If a change is necessary, you must first remove the current delegated administrator account and then designate a new one.
-
Log on to the Resource Management console and remove the original delegated administrator account of Cloud Config by using the management account.
For more information, see Remove a delegated administrator account.
NoteThis operation only revokes the permissions shared by the management account from the original delegated administrator account. The existing configurations of that account are retained.
-
In the Resource Management console, specify a new delegated administrator account.
For more information, see Add a delegated administrator account.
NoteThe new delegated administrator account inherits all the permissions of the previous one.
-
In the Cloud Config console, an employee can use the new delegated administrator account to manage account groups, view resources of member accounts in account groups, manage compliance packages and rules in account groups, and deliver resource data.