Skip to main content

RAM User Login Enabled Check

ID: rule:aliyun:ram-user-login-check
Severity: medium
IaC Types: ROS, Terraform

Description

Ensures that RAM users who do not need console access have login disabled.

Reason for Violation

Disabling console login for users who only need API access reduces security risks.

Recommendation

Remove the alicloud_ram_login_profile resource to disable console login for API-only users.

Resource Types

  • ROS: ALIYUN::RAM::User
  • Terraform: alicloud_ram_login_profile