All Products
Search
Document Center

Cloud Config:ram-user-specified-permission-bound

Last Updated:Nov 10, 2025

Checks whether the policies that are attached to each RAM user include specified high-risk permissions. If not, the evaluation result is Compliant.

Scenarios

This rule applies when you need to grant permissions to each RAM user based on the principle of least privilege (PoLP). This prevents security risks that may occur due to excessive permissions.

Risk level

Default risk level: medium.

When you apply this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If the policies that are attached to each RAM user exclude specified high-risk permissions, the evaluation result is Compliant.
  • If the policies that are attached to each RAM user include specified high-risk permissions, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see Incompliance remediation.

Rule details

ItemDescription
Rule nameram-user-specified-permission-bound
Rule identifierram-user-specified-permission-bound
TagRAM and User
Automatic remediationNot supported
Trigger TypeConfiguration change and periodic execution
Evaluation frequencyInterval of 24 hours
Supported resource typeIf you use a RAM user, perform the following steps to obtain an O&M token:
Input parameterAction
Note Separate multiple values with commas (,).

Incompliance remediation

Revoke high-risk permissions from a RAM user. For more information, see Revoke permissions from a RAM user.