The Control Policy feature is disabled by default. You can use this feature after you enable it.

Background information

After the Control Policy feature is enabled, a resource directory has the following changes:

  • The system automatically attaches the system control policy FullAliyunAccess to folders and member accounts in the resource directory. This policy allows all operations on all your cloud resources.
  • When you create a folder or member account, the system automatically attaches the system control policy FullAliyunAccess to the folder or member account.
  • After an invited Alibaba Cloud account joins a resource directory, the system automatically attaches the system control policy FullAliyunAccess to this member account.
  • When you remove a member account, the system automatically detaches all control policies that are attached to this account.

Procedure

  1. Log on to the Resource Management console.
  2. In the left-side navigation pane, choose Resource Directory > Control Policy.
  3. On the page that appears, click Enable Control Policy.
  4. In the message that appears, click OK.
  5. Click the Refresh icon and view the status of the Control Policy feature.

What to do next

You can create a custom control policy. For example, you can forbid an operation on a resource. Then, you can attach this custom control policy to a folder or member account in the resource directory to manage the operation permissions of member accounts on this resource. For more information, see the following topics: