To address challenges such as fragmented security management and slow incident response in multi-cloud environments, Security Center supports onboarding e-Surfing Cloud accounts. This feature brings core assets from different cloud providers under unified management, enabling centralized threat monitoring, event detection, and policy enforcement to build a consistent cross-cloud security posture.
Step 1: Create e-Surfing Cloud credentials
To allow Security Center to securely access your e-Surfing Cloud assets, create a dedicated user group and user in the e-Surfing Cloud Identity and Access Management (IAM) console and grant them precise read-only permissions.
-
Log in to the IAM console
-
Log in to the e-Surfing Cloud console.
-
Click Account in the upper-right corner and select Account Center from the drop-down list.
-
On the Account Center page, click Identity and Access Management in the navigation bar to navigate to the IAM console.
-
-
Create a user group
-
In the IAM console, select User Groups from the left navigation pane.
-
On the User Groups page, click Create User Group in the upper-right corner.
-
In the Create dialog box, set the user group name and description.
-
User Group Name: Enter a descriptive name, such as "AliyunSAS-Integration".
-
User Group Description: Describe the purpose of the group to make it easier to manage.
-
-
-
Grant policies to the user group
-
Return to the user group list and click Grant in the Actions column for the user group you created.
-
On the Select Policy tab, select the access policies for the Security Center features you plan to use.
ImportantDue to e-Surfing Cloud authorization restrictions, a single authorization operation only supports policies with the same scope (Resource Pool-level or Global-level). When the required policies have different scopes, grant them in separate operations.
Feature
Policy
Notes
CSPM
-
ecs viewer: Observer permissions for the host service. Authorization scope: Resource Pool -
ctiam viewer: Observer permissions for identity authentication. Authorization scope: Global
-
The two policies have different scopes and must be granted in two separate operations.
-
To add threat detection support for more e-Surfing Cloud products, grant the corresponding policies by referring to Appendix: e-Surfing Cloud product access policies.
-
-
On the Set Minimum Authorization Scope tab, set the authorization scope.
WarningEvaluate the appropriate scope before saving. The system default is Global Resources.
-
ecs viewersupports the following three scopes:-
Specified Resource Pools: Access only resources in the current region.
-
Global Resources: Access all resources.
-
Specified Enterprise Projects: Access resources under the specified enterprise project.
-
-
ctiam viewersupports the following two scopes:-
Global Resources: Access all resources.
-
Specified Enterprise Projects: Access resources under the specified enterprise project.
-
-
-
-
Create a user and add it to the user group
-
In the IAM console, click Users in the left navigation pane.
-
On the Users page, click Create User in the upper-right corner.
-
On the Configure User Basic Information tab, complete the following settings and click Next.
-
Username: Enter a descriptive name, such as "AliyunSAS-User".
-
Phone Number: Required.
-
Access Method: Select OpenAPI access.
NoteIf console login is also required, select Console as well.
-
Set Password: Auto-generate password.
-
-
On the Add to User Group tab, select the user group you created in Step 2 and click Add to move it to the Selected User Groups list.
-
Click Next.
-
-
Create and save the AccessKey pair
-
Return to the user list, find the user you just created, and click View in the Actions column.
-
On the user details page, click the Security Settings tab and click Create AccessKey in the AccessKey section.
-
After the key is created, a dialog box displays the AccessKey ID and SecurityKey.
WarningSave the AccessKey pair immediately. The key information will not be shown again after you close the dialog box.
-
Step 2: Complete the onboarding in security center
-
Navigate to the authorization page:
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
On the tab, click Grant Permission and select e-Surfing Cloud.
-
-
Configure provisioning credentials:
-
In the Add Assets Outside Cloud panel, under the Select the modules to authorize section, select the Security Center modules to enable and click Next.
NoteCurrently, only CSPM (CSPM) is supported.
-
On the Submit AccessKey Pair page, enter the credential information created in Step 1.
-
Enter Sub-account Secret ID and Enter Sub-account Secret Key: Enter the AccessKey credentials obtained in Step 1.
-
Domain (Select Chinese Edition for China and International Edition for others): Select the region where your e-Surfing Cloud account is located.
-
-
After filling in the information, click Next. Security Center automatically validates the credentials and permissions.
NoteIf validation fails, refer to What should I do if the credential and permission check fails after entering the AccessKey pair?.
-
-
Configure a synchronization policy:
-
Select region: Select the region where the e-Surfing Cloud assets to be onboarded are located.
NoteThe synchronized asset data is attributed to the data center corresponding to the region selected in the upper-left corner of the Security Center console.
-
Chinese Mainland: China Mainland data center.
-
Outside Chinese Mainland: Singapore data center.
-
-
Region Management: Recommended. When enabled, assets in new regions under this e-Surfing Cloud account are automatically synchronized — no manual addition needed.
-
AK Service Status Check: Set the interval at which Security Center automatically checks the validity of the e-Surfing Cloud account API key. Select "Off" to disable the check.
-
-
After configuration is complete, click Synchronize Assets. Security Center automatically syncs the assets under the e-Surfing Cloud account.
Step 3: View and manage onboarded assets
In the Security Center console, go to the page. In the left-side All Alibaba Cloud Services navigation pane, click e-Surfing Cloud to view the onboarded e-Surfing Cloud assets. For more information, see View cloud service information.
Operations and security management
Rotate the AccessKey pair
To maintain account security, we recommend that you rotate the AccessKey pair used for integration on a regular basis.
-
In the e-Surfing Cloud IAM console, create a new AccessKey pair for the dedicated IAM user.
-
In the Security Center console, go to and find the corresponding e-Surfing Cloud account. Click Edit and update the AK/SK to the newly created credentials.
-
After verifying that the new key can successfully sync assets, return to the e-Surfing Cloud IAM console and delete the old AccessKey pair.
Update the authorization scope
To onboard a new e-Surfing Cloud product (for example, a newly purchased Distributed Cache for Redis) into Security Center management, update the authorization for that product.
-
In the e-Surfing Cloud IAM console, find the dedicated user group and grant the corresponding access policy for the new product (for example,
Distributed Cache Redis viewer). For more information about policies, see Appendix: e-Surfing Cloud product access policies. -
Security Center automatically discovers and manages the newly authorized assets during the next synchronization cycle. You can also manually trigger Sync Latest Assets on the page.
Delete the connection
If you no longer need to manage an e-Surfing Cloud account through Security Center, you can delete it.
-
On the Multi-cloud Configuration Management page in the Security Center console, find the e-Surfing Cloud account to be deleted and click Delete.
-
After deletion, Security Center stops monitoring and risk scanning for all assets under that account, and the related asset information is no longer displayed.
-
For security purposes, we recommend that you also delete or disable the dedicated IAM user in the e-Surfing Cloud IAM console.
Appendix: e-Surfing Cloud product access policies
The list of supported e-Surfing Cloud products is continuously updated. For the current list, refer to the Security Center console.
|
Policy Name |
Description |
|
|
Default viewer policy for the distributed Message Service for Kafka CTIAM product. |
|
|
Read-only user policy for Distributed Cache Service for Redis. Grants read-only permissions on instance resources. |
|
|
Observer permissions for Object Storage Service. |
|
|
Read-only access permissions for the distributed Message Service for RocketMQ-MQ2. |
|
|
Administrator permissions for Server Load Balancer. |
|
|
Observer permissions for Elastic Block Storage. Important
When setting the minimum authorization scope, set the authorization scope to Specified Enterprise Projects. |
|
|
User permissions for the host service. |
FAQ
-
Why are some onboarded e-Surfing Cloud resources not visible in Security Center?
-
Region not selected: In the Security Center onboarding configuration, check whether the region where the resource is located is selected.
-
Synchronization delay: After initial onboarding or a configuration change, asset synchronization may have some delay. Please wait for the sync to complete.
-
Insufficient permissions: Verify that the AccessKey pair has sufficient read-only permissions to query the cloud resource information.
-
-
What should I do if the credential and permission check fails after entering the AccessKey pair?
-
Permission issue: The AccessKey pair lacks the required permissions. Refer to Create authorization credentials in e-Surfing Cloud to modify or add the required access policies.
-
Account issue: Confirm that the AccessKey pair is valid and has not expired.
-
Region mismatch: The selected Domain (Select Chinese Edition for China and International Edition for others) does not match the region of your account. Switch to another available region and resubmit.
-
-
Why can't I select a policy when adding an e-Surfing Cloud access policy?
-
Cause: Due to e-Surfing Cloud operation restrictions, a single authorization operation only allows selecting policies with the same scope type (Resource Pool-level or Global-level).
-
Solution: Perform two separate authorization operations, entering each policy separately.
-