You can unbind a multi-factor authentication (MFA) device for a RAM user if the user no longer needs MFA or wants to switch to a different MFA device or authentication method.
This topic describes how to unbind an MFA device for a RAM user. After the device is unbound, the user must bind a new MFA device the next time they log on if their security settings still require MFA. If you want to completely disable MFA for the RAM user (not recommended), you must modify the RAM user's security settings and console logon settings. For more information, see How do I disable MFA for a RAM user when they log on to the console?.
Unbinding an MFA device for a RAM user removes a layer of authentication and reduces account security.
Unbind a virtual MFA device
By RAM user
RAM users with the required permissions can unbind their own virtual MFA device. To learn how to grant these permissions, see Global security.
-
Log on to the RAM user logon page as a RAM user.
-
Hover over your profile picture in the upper-right corner and click Security.

-
In the MFA Information section, click Unbind to the right of MFA Device.
-
In the Virtual MFA Authentication dialog box, enter the verification code and click OK.
By administrator
An Alibaba Cloud account or a RAM administrator can unbind a virtual MFA device for a RAM user in the RAM console.
-
Log on to the RAM console as an Alibaba Cloud account or a RAM administrator.
-
In the left-side navigation pane, choose .
-
In the User Logon Name/Display Name column, click the name of the desired RAM user.
-
In the Security Information Management section on the Authentication tab, click Unbind to the right of Unbind.
Unbind a security email
By RAM user
RAM users with the required permissions can unbind their own security email. To learn how to grant these permissions, see Global security.
-
Log on to the RAM user logon page as a RAM user.
-
Hover over your profile picture in the upper-right corner and click Security.

-
In the MFA Information section, click Unbind to the right of Security Email.
By administrator
An Alibaba Cloud account or a RAM administrator can unbind a security email for a RAM user in the RAM console.
-
Log on to the RAM console as an Alibaba Cloud account or a RAM administrator.
-
In the left-side navigation pane, choose .
-
In the User Logon Name/Display Name column, click the name of the desired RAM user.
-
On the Authentication tab, in the Security Information Management section, click Unbind to the right of Security Email.
-
In the Unbind Security Email dialog box, confirm the information and click Unbind.
Unbind a U2F security key
By RAM user
RAM users with the required permissions can unbind their own U2F security key. To learn how to grant these permissions, see Global security.
-
Log on to the RAM user logon page as a RAM user.
-
Hover over your profile picture in the upper-right corner and click Security.

-
In the MFA Information section, click Unbind to the right of MFA Device.
By administrator
An Alibaba Cloud account or a RAM administrator can unbind a U2F security key for a RAM user in the RAM console.
-
Log on to the RAM console as an Alibaba Cloud account or a RAM administrator.
-
In the left-side navigation pane, choose .
-
In the User Logon Name/Display Name column, click the name of the desired RAM user.
-
On the Authentication tab, in the Security Information Management section, click Unbind to the right of MFA Device.
Unbind a passkey
-
Go to the RAM user logon page and sign in.
-
Hover over your profile picture in the upper-right corner and click Security.

-
In the Passkey section, find the passkey that you want to remove and click Delete in the Operation column.

-
In the Delete the passkey dialog box, click OK.