All Products
Search
Document Center

Create and authorize RAM sub-account

Last Updated: Jul 04, 2018

This topic explains how to create a RAM sub-account, and authorize this sub-account to access ARMS and call OpenAPI.

About this task

For security reasons, we recommend you create a RAM sub-account with the primary account, and handle the daily operation and maintenance work with this sub-account, or call OpenAPI with the sub-account’s own AK and SK. But without authorizing the sub-accounts beforehand, if you log on with this RAM sub-account on the RAM user logon page and access the ARMS console, or call OpenAPI with this sub-account’s AK and SK, then you will receive an error message about authorization issue.

Therefore, after creating a RAM sub-account, you must grant the AliyunARMSFullAccess permission to this sub-account.

Procedure

A. Create a RAM sub-account

  1. In the left-side navigation pane of the RAM console, choose Users. The User Management page is displayed.
  2. Click Create User in the upper-right corner of the page. The Create User dialog box is displayed.
  3. In the dialog box, enter the user information, select Automatically generate an AccessKey for this user, and then click OK. The Phone Verification dialog box is displayed.
  4. In the dialog box, click Send verification code, enter your received verification code, and then click Confirm. The created user is displayed on the User Management page.
  5. Click the user name or Manage in the Actions column. The User Details page is displayed.
  6. In the Web Console Logon Management area, click Enable Console Logon, enter the password in the dialog box, and then click OK.

B. Authorize the sub-account to access ARMS or call OpenAPI

  1. In the left-side navigation pane of the RAM console, choose Users. The User Management page is displayed.
  2. Find the user to be authorized on the page, and click Authorize in the Actions column. The Edit User-Level Authorization dialog box is displayed.

  3. In the dialog box, search for the AliyunARMSFullAccess authorization policy with keywords, click the > button to move it to the Selected Authorization Policy Name list on the right, and then click OK.