All Products
Search
Document Center

Resource Access Management:Revoke permissions from a RAM user group

Last Updated:Feb 02, 2026

When permissions are no longer required, you can detach policies from a Resource Access Management (RAM) user group to revoke access for all users in that group.

Warning

When you detach a policy from a user group, all users in that group immediately lose the permissions granted by the policy. This action can affect applications or services that rely on the group's permissions. Before you proceed, ensure that the users in the group no longer require these permissions.

Method 1: Detach a policy on the group details page

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Identities > Groups.

  3. On the Groups page, click the name of the target group.

  4. On the Permissions tab, find the policy that you want to detach and then click Revoke Permission in the Actions column.

  5. In the Revoke Permission dialog box, click Revoke Permission.

Method 2: Detach a policy on the Grants page

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Permissions > Grants.

  3. On the Permission page, do one of the following:

    • To detach a single policy, find the policy and click Revoke Permission in the Actions column.

    • To detach multiple policies, select the checkboxes for the policies that you want to remove, and click Revoke Permission at the bottom of the list.

  4. In the Revoke Permission dialog box, click Revoke Permission.