Help Center/ Cloud Firewall/ User Guide/ System Management/ Critical Operation Protection
Updated on 2026-07-15 GMT+08:00

Critical Operation Protection

Scenario

CFW supports critical operation protection. When you perform a critical operation on the console, you need to provide a credential for verification. The operation can be performed only after your identity is verified. Enable this function for your account security. It will take effect for both the account and users under the account.

So far, CFW can protect the following critical operations: disabling EIP protection, disassociating a VPC, deleting a protection rule, and deleting a blacklist or whitelist.

Notes and Constraints

  • Only an administrator can configure critical operation protection, and IAM users can only view the configurations. If an IAM user needs to modify the configurations, the user can request the administrator to perform the modification or grant the required permissions.

    Federated users do not need to be authenticated when performing critical operations.

  • Only operations that are performed on the console can be protected by this function.

Enabling Operation Protection

Operation protection is disabled by default. Perform the following operations to enable it:

  1. Log in to the CFW console.
  2. On the console, hover your cursor over the username in the upper right corner, and choose Security Settings.

    Figure 1 Security settings

  3. On the Security Settings page, click the Critical Operations tab. In the Operation Protection row, click Enable.
  4. On the Operation Protection page, select Enable.

    In this case, if you or the IAM users under your account perform critical operations such as disabling EIP protection or deleting a protection rule, you are required to enter a verification code, avoiding risks and loss for your service.

    • When performing a critical operation, you will be asked to choose a verification method from email, SMS, and virtual MFA device.
      • If you only bind a phone number, only SMS verification is available for verification.
      • If you only bind an email address, only email is available for verification.
      • If you have not bound any method, bind one to perform critical operations.
    • If you want to change the mobile number, email address, or virtual MFA device, see Basic Information.

Verifying the Operation Protection

After operation protection is enabled, when you perform a mission-critical operation, such as disabling EIP protection, the system will verify your identity.

  • If you have bound an email address, enter the email verification code.
  • If you have bound a mobile number, enter the SMS verification code.
  • If you have bound a virtual MFA device, enter the 6-digit dynamic verification code on the MFA device.
    Figure 2 Verifying the operation protection

Disabling Operation Protection

Perform the following operations to disable operation protection:

  1. Log in to the CFW console.
  2. On the console, hover your cursor over the username in the upper right corner, and choose Security Settings.

    Figure 3 Security settings

  3. On the Security Settings page, click the Critical Operations tab. In the Operation Protection row, click Change.
  4. On the Operation Protection page, choose Disable, click OK, and pass the verification.