All Products
Search
Document Center

Resource Access Management:Revoke permissions from a RAM user

Last Updated:Jan 28, 2026

To modify a Resource Access Management (RAM) user's access, you can detach policies to revoke their permissions. This is necessary when a user's role changes or their access is no longer required.

Warning

When you detach a policy, the RAM user immediately loses the permissions granted by that policy. This action can affect applications or services that rely on the user's credentials. Before you proceed, ensure that the user no longer requires these permissions.

Method 1: Detach a policy on the user details page

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, click the name of the target RAM user.

  4. On the Permissions tab, find the policy that you want to detach, and click Revoke Permission in the Actions column.

  5. In the Revoke Permission dialog box, click Revoke Permission.

Method 2: Detach a policy on the Grants page

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Permissions > Grants.

  3. On the Permission page, do one of the following:

    • To detach a single policy, find the policy and click Revoke Permission in the Actions column.

    • To detach multiple policies, select the checkboxes for the policies that you want to remove, and click Revoke Permission at the bottom of the list.

  4. In the Revoke Permission dialog box, click Revoke Permission.