All Products
Search
Document Center

Cloud Config:ram-user-login-check

Last Updated:Jun 16, 2026

Checks whether a RAM user has both console access and API access enabled at the same time.

Scenario

Enabling both console access and API access for a single RAM user increases security risk. These two access methods typically serve different roles, such as O&M and R&D. To isolate permissions and follow the principle of least privilege, grant each RAM user only one type of access.

Risk level

Default risk level: low.

You can change the risk level when you apply this rule.

Compliance evaluation logic

  • If console access and API access are not enabled for a RAM user at the same time, the evaluation result is compliant.
  • If console access and API access are enabled for a RAM user at the same time, the evaluation result is non-compliant. For more information about how to correct the non-compliant configuration, see Non-compliance remediation.

Rule details

Item Description
Rule name ram-user-login-check
Rule ID ram-user-login-check
Tag RAM and User
Automatic remediation Not supported
Trigger type Configuration change
Supported resource type RAM user
Input parameter None

Non-compliance remediation

Enable only console access or API access for the RAM user. For more information, see Log on to the Alibaba Cloud console as a RAM user or Disable a RAM user's access key.