This topic describes the basic concept, scenarios, and limits of account groups, and the impacts of member changes on Cloud Config. The member can belong to a resource directory or an account group.
Basic concept
An account group is a collection of member accounts. In a resource directory, the management account can add all or some member accounts to an account group for centralized compliance management. An account group is also a resource pool formed by gathering resources from multiple member accounts.
The management account can view the resource lists, resource details, resource configuration timelines, resource compliance timelines, and associated resources of all member accounts in the account group. It can also create rules and compliance packages in the account group. These rules and compliance packages take effect on resources of all member accounts in the account group for continuous compliance evaluation.
Scenarios
A management account can add all or some members in a resource directory to an account group. An account group can be used to manage resource compliance across Alibaba Cloud accounts. It allows enterprises to manage compliance and collect data for multiple services and Alibaba Cloud accounts in a comprehensive manner.
Account groups can be used in the following scenarios:
You can view the global resources of all members in an account group. A management account can view the resources of all members in an account group, or filter or search for resources in a resource list. A management account can also view the details and configuration timeline of resources.
You can set a compliance baseline for all members in an account group. A management account can create rules and compliance packages in an account group. These rules and compliance packages take effect on the resources of all members in the account group. Members cannot modify or delete the rules and compliance packages. This way, a management account can forcibly set a unified compliance baseline for multiple members.
You can view the compliance check results of all members. A management account can view the compliance check results of a rule on the resources of each member. A management account can also view the compliance check results of a rule on all the resources of multiple members. This facilitates centralized compliance management for multiple services and accounts.
You can collect the resource data of all members. After an account group is created, the management account takes over some Cloud Config permissions of members. The management account can configure a unified data delivery method for all the members in the account group. Then, the resource configuration history of all members is delivered to the management account or a member that is used to store enterprise configuration data.
You can send the resource events of all accounts. A management account can send the resource change events and resource non-compliance events of all members to a Simple Message Queue (formerly MNS) topic.
If you are using Cloud Config for Enterprise, a new account group that contains all the members of a resource directory is created by default in an account group. Existing rules are still valid.
Limits
Account groups have the following limits:
Only a management account in a resource directory can create an account group. The management account can add all or some members of a resource directory to the account group.
Each management account can create a maximum of five account groups. Each account group can contain a maximum of 200 members.
Impacts of member changes in a resource directory on Cloud Config
The following table lists the impacts of member changes in a resource directory on Cloud Config.
Item | Impact |
Add a member to a resource directory |
|
Change the resource directory to which a member belongs | Cloud Config is not affected. Cloud Config does not perform operations. |
Remove a member from a resource directory | Cloud Config is affected. If you remove a member from a resource directory, the management account loses the management permissions on the member. Then, the member is automatically removed from all account groups. |
Impacts of member changes in an account group on Cloud Config
The following table lists the impacts of member changes in an account group on Cloud Config.
Item | Impact |
Add a member to no account group | The member uses Cloud Config as an independent Alibaba Cloud account. |
Add a member to an account group |
|
Remove a member from an account group |
|