All Products
Search
Document Center

Security Center:Multi-account security management

Last Updated:Jun 29, 2026

Use the multi-account management feature of Security Center to centrally purchase security products, configure security protection, and handle risks for multiple Alibaba Cloud accounts.

Use cases

Centralized security configuration and risk management

  • Centralized management of security protection and risks

    Member account data and configurations are isolated, but a delegated administrator account in Security Center can centrally manage security settings, handle risks, and perform hardening across all member accounts.

  • Cross-account log ingestion, storage, and threat analysis

    Agentic SOC ingests data from member accounts into a delegated administrator account for centralized storage and analysis, helping identify cross-account security risks and providing a global view of security events.

Centralized billing and shared quotas

A delegated administrator can purchase Security Center feature quotas and allocate them to member accounts, eliminating individual purchases and simplifying cost allocation.

Important
  • If a member account has already purchased a Security Center instance, you cannot allocate a quota to it. To allocate a quota, the member account must first unsubscribe from its subscription instance and disable any pay-as-you-go instances.

  • To centrally pay for all cloud products used by member accounts, use the finance trusteeship feature. Finance Trusteeship overview.

  • For security reasons, we recommend that you use a Security Center delegated administrator account, not the management account, to purchase quotas.

Example of a multi-account architecture

A security expert uses a dedicated security account (delegated administrator) to centrally manage your organization's production and testing accounts, streamlining risk detection, response, and hardening. For more complex multi-account scenarios, submit a ticket for technical support.

image

Prerequisites

Step 1: Add a delegated administrator account

The Resource Directory management account designates a member account as the delegated administrator for a trusted service. Once designated, this account can access organizational information and perform management tasks on behalf of the organization.

  1. Log on to the Resource Management console by using your management account.

  2. In the navigation pane on the left, choose Resource Directory > Trusted Services.

  3. On the Trusted Services page, find Security Center and click Manage in the Actions column.

  4. In the Delegated Administrator Account section, click Add.

  5. In the Add delegated administrator account panel, select the member account that you want to set as a delegated administrator, and then click Confirm.

    After the account is added, it can access the multi-account management feature in Security Center and manage resources within your Resource Directory organization.

    Note

    You can add a maximum of 10 delegated administrator accounts for Security Center.

Step 2: Configure the account management scope

Configure the scope of member accounts that a delegated administrator can manage.

Important
  • A delegated administrator can only view and manage member accounts within its scope and cannot access accounts managed by other delegated administrators. If the management account configures the scope, only the management account can view and manage those member accounts.

  • A member account can be managed by only one delegated administrator at a time.

  1. Log on to the Security Center console by using a delegated administrator account.

  2. In the left-side navigation pane, choose System Settings > Multi-account Management. In the upper-left corner of the console, select the region where the assets that you want to protect are located: Chinese Mainland or Outside Chinese Mainland.

  3. (Required for first-time use) On the Multi-account Management page, click Enable Management in Security Center.

  4. On the Configure tab, in the Total Monitored Accounts section, click Account Management.

  5. In the Multi-account Management Settings panel, select the member accounts that you want the current account to manage.

    image

  6. (Optional) Turn on Automatic Management of New Accounts to set a management policy for new accounts.

    After you turn on this switch, click Configure Policy, select the target Resource Directory nodes, and click OK. When a new account is added to a selected node, it is automatically added to the list of managed accounts.

  7. Click OK.

    You can view the member accounts within the management scope on the Configure tab.

    image

Step 3 (Optional): Allocate quotas

A delegated administrator can centrally purchase subscription quotas for Security Center features and then allocate them to member accounts.

Quota allocation limits

Only a delegated administrator can allocate subscription quotas to member accounts within its management scope. Target accounts must not have purchased a Security Center subscription or enabled pay-as-you-go services (except agentless detection and Serverless security). The following table lists features that support quota allocation.

Feature

Minimum and increment

Description

Host and container security

  • Ultimate server quota

  • Enterprise server quota

  • Advanced server quota

  • Anti-virus server quota

  • Minimum: 1 server or 1 core

  • Increment: 1 server or 1 core

  • Unified billing and quota allocation are not supported for pay-as-you-go instances of Security Center.

  • Quota allocation is not supported for the following features:

    • Vulnerability remediation

    • agentless detection (pay-as-you-go only)

    • Serverless security (pay-as-you-go only)

Note
  • To use vulnerability remediation, assign an Advanced, Enterprise, or Ultimate edition quota to the member account and bind it to servers. These editions provide unlimited remediation. The Anti-virus edition does not support vulnerability remediation.

  • If a member account with an allocated quota needs to use agentless detection and Serverless security, the member account can enable the corresponding pay-as-you-go services.

anti-ransomware capacity

  • Minimum: 10 GB

  • Increment: 10 GB

Note

After you purchase the managed anti-ransomware service, the anti-ransomware capacity allocated to member accounts automatically uses the managed service capabilities.

Managed anti-ransomware service

Log analysis capacity

  • Minimum: 10 GB

  • Increment: 10 GB

container image scan

  • Minimum: 20

  • Increment: 20

application protection

  • Minimum: 1

  • Increment: 1

cloud honeypot

  • Minimum: 20

  • Increment: 20

web tamper proofing

  • Minimum: 1 server

  • Increment: 1 server

CSPM

  • Minimum: 15,000

  • Increment: 55,000

malicious file detection

  • Minimum: 100,000

  • Increment: 100,000

Agentic SOC - Log ingestion traffic

  • Minimum: 100 GB

  • Increment: 100 GB

Agentic SOC - Log storage capacity

  • Minimum: 1,000 GB

  • Increment: 1,000 GB

View and purchase quotas

  1. Log on to the Security Center console by using a delegated administrator account.

  2. On the Overview page, in the Subscription section, view the subscription quotas for your Security Center instance.

    This area displays all purchased features and quotas. For example, for the Subscription displayed to the right of Anti-ransomware, 150 indicates the total anti-ransomware capacity (GB) and 132.9 indicates used capacity (including regions in and outside mainland China).

    image

  3. To purchase more quotas, click Buy Now or Upgrade Now and complete the purchase.

    Purchase Security Center and Upgrade and downgrade Security Center.

Allocate quotas

Warning

The multi-account quota allocation feature is in beta testing. To use this feature, contact technical support.

  1. Log on to the Security Center console by using a delegated administrator account.

  2. On the System Settings > Multi-account Management page, on the Configure tab, click Quota Management under Total Monitored Accounts to go to the Multi-account Quota Management page.

    image

  3. On the Multi-account Quota Management page, click Edit.

  4. Click Add Account. In the Add Account dialog box, select the member accounts to which you want to allocate quotas, and then click OK.

    • You can allocate quotas only to member accounts that are managed by the current delegated administrator. You cannot allocate quotas to unmanaged accounts or accounts managed by other delegated administrators.

    • You can select only member accounts that have not purchased a Security Center subscription instance and have not enabled pay-as-you-go services, except for agentless detection and Serverless security.

      image

  5. In the Quota Management section, allocate quotas to the member accounts.

    In the Purchased Quota section, you can view the features and quotas purchased for the current account.

    The first row in the Quota Management section shows remaining quota available for allocation and cannot be edited. Unallocated quotas stay with the current account. The total allocated to member accounts cannot exceed the first-row value. Quota allocation limits.

    image

  6. Click Save.

    After you allocate server quotas, the system automatically and randomly binds them to servers in the member account to maximize usage. Additional quotas allocated later are not automatically bound. You must switch to the member account to manually bind new quotas. Manage quotas for host and container security.

Step 4: Manage security for member accounts

View risk overview

  • View a summary of risk information for member accounts

    On the Overview tab of the System Settings > Multi-account Management page, view security scores, at-risk assets, alerts, vulnerabilities, and baseline issues for all managed member accounts to identify high-risk accounts.

    image

    On the Configure tab of the Settings > Multi-account Management page, you can view statistics on security risks within member accounts.

    image

  • View risk details for a member account

    In the upper-left corner of the console, switch to a member account to view its security operations on the Member page. Overview (new).

    image

Manage security for member accounts

  1. Log on to the Security Center console by using a delegated administrator account.

  2. In the left-side navigation pane, choose System Settings > Multi-account Management. In the upper-left corner of the console, select the region where the assets that you want to protect are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Configure tab of the Multi-account Management page, click Settings in the Actions column of a member account.

  4. In the Settings panel, configure agent, vulnerability, and baseline scan settings for the member account, and then click OK.

    image

  5. In the upper-left corner of the console, switch to the member account to access its console.

    After switching to the member account console, the delegated administrator can perform asset inventory, risk detection, hardening, real-time protection, and active detection and response. Features.

More operations

Using allocated quotas

After a delegated administrator allocates quotas, the member account can use them. If quota is insufficient, request more from the management account. Member accounts cannot purchase, renew, or upgrade Security Center instances independently. To avoid wasting quotas, follow the instructions below for each feature.

  • Manage quotas for host and container security: On the Overview or Host page, view and manage server protection quotas, including Ultimate, Enterprise, Advanced, and Anti-virus server quotas.

  • Anti-ransomware: Create a protection policy to back up core data files on your servers or databases. For instructions, see the following topics:

  • Log analysis: Delivery of all log types is enabled by default. No manual action is required.

    Important

    A delegated administrator cannot use the log analysis feature of a member account by switching accounts in the upper-left corner of the console. The member account must log on to its own console to use this feature.

  • Container image scan: After you perform an image scan, the corresponding quota is used to detect security risks in the image.

  • Application protection: You must add your application to the application protection feature.

  • Cloud honeypot: Deploy cloud honeypots on your servers to trap attacks.

  • Web tamper proofing: Add protection to your servers to prevent malicious content from being injected into your website and ensure normal operation.

  • CSPM: Configure risk check policies for cloud product configurations, system baselines, and attack path scan rules to perform CSPM.

  • Malicious file detection: Detect malicious files by calling the SDK on your servers to scan offline files or by scanning files stored in OSS from the Security Center console.

  • Agentic SOC log storage capacity: To enable log delivery for Security Center and standardized logs.

  • Agentic SOC log ingestion traffic: To add cloud product logs to Agentic SOC.

Delete a member account

Log on with the delegated administrator account, go to the Configure tab of the System Settings > Multi-account Management page, and click Delete in the Actions column of a member account to remove it.

Important

If a member account has been allocated quotas, deleting the account or its quota allocation will remove the allocated quotas. All assets under that member account will lose protection, the system will automatically release all quotas, and all logs will be cleared. Proceed with caution.

Delete a quota allocation

Log on with the delegated administrator account and go to the Overview page. In the Subscription section, click Multi-account Management. In the Quota Management section, move the pointer over the account name, click the image icon, and click OK in the confirmation dialog box.

image

Related documents