All Products
Search
Document Center

Web Application Firewall:Multi-account management

Last Updated:Jun 24, 2026

When you use cloud product access, only cloud product instances under your current Alibaba Cloud account can be onboarded by default. To onboard cloud product instances from other Alibaba Cloud accounts, configure multi-account management to manage the target accounts under the current Web Application Firewall (WAF) system for unified access and protection configuration management across accounts.

Scope

  • Edition requirement: Only WAF Enterprise and Ultimate editions support multi-account management. Other editions do not support this feature.

  • Verification requirement: To enable a resource directory, you must use an Alibaba Cloud account that has completed enterprise-type verification.

  • Account affiliation: The management account and member accounts must belong to the same resource directory and must be under the same verified enterprise entity.

  • Instance restriction: No running WAF instances are allowed under member accounts. If any exist, you must release them before onboarding.

Post-onboarding restrictions and management rules

  • Instance purchase restriction: After a member account is onboarded, it cannot purchase a WAF instance in the same region as the management account. For example, if the management account has purchased a Chinese mainland WAF instance, the member account cannot purchase a Chinese mainland instance but can purchase instances outside the Chinese mainland.

  • Console permission restriction: After a member account's cloud product assets are onboarded to the management account's WAF instance, the member account can only view protection configurations, overview, and security reports in the management account's WAF console.

  • Automatic asset removal: If the management account deletes a member account in the WAF console, the system automatically removes the cloud product assets onboarded for protection under that member account.

Procedure

Step 1: Management account enables a resource directory

Before using multi-account management, you must consolidate all Alibaba Cloud accounts of your enterprise into the same resource directory. Use your enterprise management account to log on to the Resource Management console and enable the resource directory. For detailed steps, see Enable Resource Directory.

Step 2: Invite members

After the invited party successfully joins the resource directory, it becomes a resource directory member and is managed centrally by the resource directory.

Use the management account to log on to the Resource Management console and build your organizational structure by inviting existing accounts or creating new accounts.

  • Invite existing accounts: For detailed steps, see Invite an Alibaba Cloud account.

  • Create new member accounts: If no member accounts need to be invited, you can directly create new members in the resource directory. For detailed steps, see Create a member.

  • Build organizational structure: If you need to classify and manage members by business relationships, see Create a folder.

Step 3: Add a delegated administrator account (optional)

If you do not want the primary account that enabled the resource directory to directly enable and manage the WAF service, you can set up a delegated administrator account to separate organizational management from business management tasks, which aligns with security best practices. If you plan to deploy WAF directly under the account that enabled the resource directory, skip this step.

Example account usage plan:

  • Primary account: Responsible for creating the resource directory, managing funds, and global user permissions.

  • Security account (member account): Acts as the delegated administrator to centrally manage security products such as WAF, Cloud Firewall, and Bastionhost.

  • Business account (member account): Such as Business Account 1, Business Account 2, and so on, used for deploying actual business resources such as ECS instances.

For detailed steps, see Manage delegated administrator accounts.

Step 4: Add member accounts in the WAF console

Use one of the following accounts to log on to the console:

  • If no WAF administrator has been delegated, use the management account that created the resource directory.

  • If a WAF administrator has been delegated, use the delegated member account.

  1. Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.

  2. In the navigation pane on the left, click Multi-account Management..

  3. On the Multi-account Management page, click Add Member.

  4. In the Add Member dialog box, select the member account to import from the Available Members list on the left, use the arrow button in the middle to add it to the Selected Members list on the right, and click OK.

Step 5: Onboard cloud product assets from member accounts

Perform the corresponding onboarding operation based on the cloud product asset type:

  • For the Application Load Balancer (ALB), Classic Load Balancer (CLB), Network Load Balancer (NLB), and Elastic Compute Service (ECS) cloud products, assets can be automatically synced to the WAF deployment account. Log on to the WAF deployment account's console to complete the onboarding for the member account assets.

  • For the Microservices Engine (MSE) - Cloud-native Gateway, Cloud-native API Gateway, Global Accelerator (GA), and Function Compute. First, log on to the member account's corresponding product console to complete onboarding, then view the details in the WAF deployment account's console.

For detailed onboarding operations, see Overview.

FAQ

What alternatives are available if I cannot configure multi-account management?

If you cannot configure multi-account management, you can use CNAME access as an alternative. This method supports onboarding publicly accessible domain names and is not limited by cross-account or cross-cloud environments.