OVH Cloud access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On OVH Cloud, Black Cat runs 17 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OVH Cloud connector needs.
Checks (17)
severity: critical MFA Not Enabled fix difficulty: easy #
Enable multi-factor authentication on the OVHcloud account
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Click your account name in the top-right corner and select "My account"
- Navigate to Security > Two-Factor Authentication
- Click "Add a security method" and choose TOTP (authenticator app) or U2F hardware key
- Follow the wizard to register and activate the MFA device
- Confirm the device appears as active under Two-Factor Authentication settings
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Only SMS MFA Enabled fix difficulty: easy #
Add a TOTP or U2F second factor in addition to SMS-based MFA
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Click your account name in the top-right corner and select "My account"
- Navigate to Security > Two-Factor Authentication
- Click "Add a security method" and select TOTP app or U2F hardware key
- Follow the enrollment wizard to register the stronger MFA device
- Verify both the SMS and new method are listed as active
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high No IP Restrictions fix difficulty: medium #
Configure IP access restrictions to limit Control Panel access to trusted networks
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Click your account name in the top-right corner and select "My account"
- Navigate to Security > Access restrictions
- Click "Add a restriction" and enter the trusted IP address or CIDR range
- Set the restriction type to "Management interface" to protect Control Panel access
- Save the configuration and verify access from an allowed IP
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high API Credential No Expiry fix difficulty: medium #
Set an expiration date for OVHcloud API credentials to limit long-lived access
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > API > My credentials (or visit api.ovh.com/createToken/)
- Identify credentials that have no expiration date
- Revoke the non-expiring credential by clicking "Delete"
- Re-create the credential at api.ovh.com/createToken/ with an explicit validity period
- Update any applications using the credential with the new key
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium API Credential Never Used fix difficulty: easy #
Revoke API credentials that have never been used to reduce unused access surface
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > API > My credentials
- Identify credentials with no recorded last-use date
- Click "Delete" on each unused credential
- Confirm the revocation when prompted
- Review application configurations to ensure no active services relied on the revoked credential
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high API Credential Overly Permissive fix difficulty: medium #
Replace wildcard API credential rules with specific path and method restrictions
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > API > My credentials and identify the overly permissive credential
- Note the application or service using this credential
- Revoke the wildcard credential by clicking "Delete"
- Re-create the credential at api.ovh.com/createToken/ with explicit paths and HTTP methods only
- Update the application with the new least-privilege credential and verify functionality
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Identity User Disabled Not Removed fix difficulty: easy #
Delete disabled identity sub-users to eliminate latent access risk
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > IAM > Users (or Account > My account > Users & Roles)
- Filter or identify users with a disabled status
- Click the disabled user and select "Delete user"
- Confirm deletion when prompted
- Verify the user no longer appears in the user list
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Identity User No Group fix difficulty: easy #
Assign identity sub-users to appropriate groups to enforce group-based access policies
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > IAM > Users
- Click the user that has no group assignment
- Select "Assign to group" or edit the user's group membership
- Choose the appropriate group that reflects the user's required access level
- Save the changes and verify the group assignment is reflected
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: info Identity User MFA Not Enabled fix difficulty: easy #
Enable multi-factor authentication for OVHcloud identity sub-users
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > IAM > Users
- Click the user who does not have MFA enabled
- In the user settings, locate the Two-Factor Authentication section
- Enable MFA and instruct the user to complete the enrollment on their next login
- Confirm MFA is active in the user detail view
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: critical IAM Policy Wildcard Actions fix difficulty: hard #
Replace wildcard actions in IAM policies with explicit least-privilege action lists
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > IAM > Policies
- Click the policy that contains wildcard (*) actions
- Edit the policy and review all statement blocks with wildcard action entries
- Replace each wildcard action with the specific actions required by the identities using this policy
- Save the updated policy and verify that assigned identities can still perform their required operations
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high IAM Policy Wildcard Resources fix difficulty: hard #
Scope IAM policies to specific resource URNs instead of wildcard resource targets
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > IAM > Policies
- Click the policy that uses wildcard (*) resource URNs
- Edit the policy and identify all statement blocks with wildcard resource entries
- Replace each wildcard resource with the explicit URNs of the resources that need access
- Save the updated policy and validate that intended access is still functional
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive OAuth2 Clients fix difficulty: medium #
Review and remove unused OAuth2 service accounts to maintain credential hygiene
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > API > OAuth2 Clients
- Review all listed OAuth2 clients and their last-use timestamps
- Identify clients that are no longer in use or have unknown ownership
- Click "Delete" on each unused client and confirm the deletion
- Document the remaining active clients and their owners for future audits
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Weak SSH Key Algorithm fix difficulty: medium #
Replace RSA or DSA SSH keys with Ed25519 or ECDSA keys for stronger cryptographic security
- Generate a new SSH key pair using a strong algorithm — run "ssh-keygen -t ed25519 -C 'your-email@example.com'"
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > My SSH Keys (or Public Cloud > SSH Keys for project-scoped keys)
- Click "Add SSH key", paste the new Ed25519 public key, and give it a descriptive name
- Update all instances that used the old key to authorise the new public key in ~/.ssh/authorized_keys
- Delete the old weak-algorithm SSH key from the OVHcloud Control Panel
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high SSH Key Size Too Small fix difficulty: medium #
Replace undersized RSA SSH keys with keys of at least 2048 bits or switch to Ed25519
- Generate a new SSH key pair with a strong key size — run "ssh-keygen -t ed25519" or "ssh-keygen -t rsa -b 4096"
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > My SSH Keys (or Public Cloud > SSH Keys for project-scoped keys)
- Click "Add SSH key", paste the new public key, and give it a descriptive name
- Update all instances that used the old small key to authorise the new public key in ~/.ssh/authorized_keys
- Delete the old undersized SSH key from the OVHcloud Control Panel
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium API Credential OVH Support Access fix difficulty: easy #
Review and revoke API credentials that grant OVH support access to your account
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > Security > API Credentials
- Select the credential flagged as granting OVH support access
- Review whether OVH support still needs API access to your account for an active support ticket
- If no longer needed, click "Delete" to revoke the credential
- If still needed, document the justification and set a calendar reminder to revoke after the ticket is resolved
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium IAM Policy Excessive Identities fix difficulty: medium #
Use identity groups instead of assigning many individual identities to a single IAM policy
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to IAM > Policies and select the policy with excessive identities
- Review the list of assigned identities and identify common roles or teams
- Create IAM groups for each identified team and add the relevant users to each group
- Replace the individual identity assignments in the policy with the group identities
- Verify that access continues to work correctly for affected users
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Identity User Password Never Changed fix difficulty: easy #
Require the identity user to change their password from the initial credential
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > Identity Users and locate the user who has never changed their password
- Contact the user and instruct them to change their password immediately
- If the user is inactive, consider disabling the account until they confirm identity
- Verify the password_last_update field is populated after the change
- Consider implementing a password rotation policy for all identity users
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2