An Alibaba Cloud account that joins a resource directory retains its root user with full permissions by default. If the root user credentials are compromised, the damage can be irreversible. To reduce this risk, convert the Alibaba Cloud account to a resource account, which disables the root user.
Prerequisites
-
Perform this operation as a RAM user in the management account with the
AliyunResourceDirectoryFullAccesspermission so that the system can trace each management operation to a specific user. For more information, see Create a RAM user. -
The following conditions must be met before you can convert an Alibaba Cloud account to a resource account:
-
The member's real-name verification information matches that of the management account.
-
The member account must have a Security phone number or Security email address configured.
-
The root user of the member account has no active AccessKeys.
If an active AccessKey exists, you must disable it on the AccessKey Management page.
-
Procedure
-
Log on to the Resource Management console.
-
In the navigation pane on the left, choose .
-
On the Resource Organization View or Member List View tab, find the target Alibaba Cloud account and click Switch in the Actions column.
-
In the Convert to Resource Account dialog box, read the risk notice, select the acknowledgment checkbox, and then click OK.
-
In the Security Verification dialog box, obtain and enter a verification code, and then click OK.
Results
After the conversion, the member account changes as follows:
-
The member type changes from Alibaba Cloud Account to Resource Account.
-
The member's root user is disabled.
With the root user disabled, you can centrally manage access to the member by creating RAM users in the management account and granting them only the necessary permissions.
FAQ
Q: How do I modify the real-name verification information for a resource account?
A resource account cannot modify real-name verification information directly. You must first convert it back to an Alibaba Cloud account. Then, log on to the console as the root user of the member account and go to Account Center > Real-name Verification to modify the enterprise entity information.