This topic describes how to create a RAM user. A RAM user is an entity that you create in RAM to represent a person or application. A RAM user can access Alibaba Cloud resources after being granted the relevant permissions.

Procedure

  1. Log on to the RAM console by using an Alibaba Cloud account.
  2. In the left-side navigation pane, click Users under Identities.
  3. Click Create User.
    Note You can click Add User to create multiple RAM users at a time.
  4. Specify the Logon Name and Display Name parameters.
  5. In the Access Mode section, select Console Password Logon or Programmatic Access.
    • Console Password Logon: If you select this access mode, you must also complete the basic logon security settings. These settings specify whether to use a system-generated or custom logon password, whether the password must be reset on the next logon, and whether to enable multi-factor authentication (MFA).
      Note If you select Custom Logon Password in the Console Password section, you must specify a password. The password must meet the strength requirements that you have specified in Identities > Settings. For more information, see Set a password policy for RAM users.
    • Programmatic Access: If you select this access mode, an AccessKey pair is automatically created for the RAM user. The RAM user can call API operations or use SDKs to access Alibaba Cloud resources.
    Note We recommend that you select only one access mode for the RAM user to ensure the security of your Alibaba Cloud account. This prevents a RAM user from using the AccessKey pair to access Alibaba Cloud resources after the RAM user leaves the organization.
  6. Click OK.

What to do next

  • You can add the RAM user to one or more RAM user groups and grant permissions to the RAM user. For more information, see Add a RAM user to a RAM user group.
  • You can attach one or more policies to grant the RAM user access to the Alibaba Cloud resources specified in the policies. For more information, see Grant permissions to a RAM user.