All Products
Search
Document Center

Resource Access Management:Quick start: Create a RAM user and grant permissions

Last Updated:Sep 08, 2026

Create a RAM user and grant the minimum permissions needed for fine-grained access control over your cloud resources.

Why use RAM users?

An Alibaba Cloud account is similar to the root user in a Linux system — it has full permissions but is not suitable for daily use. When multiple employees need to collaborate on cloud resources, use Resource Access Management (RAM) to create RAM users under your Alibaba Cloud account and grant each user only the minimum permissions required for their tasks.

Item

Alibaba Cloud account

RAM user

Identity role

Owner of all resources. Has full ownership and the highest permissions.

User of resources and services. Permissions are granted by the Alibaba Cloud account. Usually corresponds to a specific person or application.

Owns cloud resources

Yes

No. Resources are owned by the Alibaba Cloud account.

Default permissions

Full permissions. Cannot be restricted.

No permissions by default. Must be granted by the Alibaba Cloud account.

Recommended use

Key management operations only: authorization, payment, and account management.

Daily development, Operations and Maintenance (O&M), deployment, and other tasks.

Procedure

  1. Create a RAM user: Use Get Started in the console to create a RAM User with Auditing Administrator permissions.

  2. Log on as the RAM user: Log on to the console as the newly created RAM user and complete the initial setup.

  3. Verify the RAM user's permissions: Verify that the permissions were granted successfully.

Note

An existing Alibaba Cloud account cannot be directly converted into a RAM user, nor can it be merged into your current Alibaba Cloud account. To create identities for people who already have their own Alibaba Cloud accounts, create new RAM users under your Alibaba Cloud account and grant them permissions. To centrally manage the billing and finances of multiple existing Alibaba Cloud accounts, use the Invite Members feature of Resource Directory to add these accounts to a resource directory.

Step 1: Create a RAM user

Quickly create a user and grant permissions

  1. Log on to the RAM console with your Alibaba Cloud account.

  2. On the Overview page, click Get Started > Cloud functional users > Show All Workflows, and select your target scenario.

    The following example uses the Auditing Administrator scenario. An Auditing Administrator has full permissions for CloudConfig, ActionTrail, and Log Service, and can view the status of all Alibaba Cloud resources.

    The Workflow Preview on the left shows the steps for the Auditing Administrator scenario: Create a user, create user logon settings, create a user group, add the user to the user group, create a custom policy, and attach the policy to the user group.

    The Get Started wizard also provides a Security Administrator scenario for users responsible for cloud security. This scenario grants full permissions for security services, including the permissions to activate and purchase cloud security services.

    There is no preset scenario template for a system administrator. If you are looking for this role, use the Super User scenario instead. A super user can create, view, and perform operations on all cloud services, but cannot manage identities and permissions, manage the account structure, or perform account linking.

    The following table compares the administrator scenarios.

    Scenario

    Permission scope

    Intended role

    Auditing Administrator

    Full permissions for CloudConfig, ActionTrail, and Log Service; can view the status of all resources

    Compliance auditor

    Security Administrator

    Full permissions for security services, including activating and purchasing cloud security services and configuring security rules

    Security lead

    Super User

    Permissions to create, view, and perform operations on all cloud services; cannot manage identities and permissions

    System operations engineer

  3. View or modify the configuration parameters.

    All preset parameters are visible, but only some can be modified. Check the console to see which parameters you can change.

  4. Click Perform.

  5. View the configuration progress. After the configuration is complete, save the RAM user's username and logon password.

Note
  1. For a RAM user created through the quick start, you can modify their configuration later in the RAM console. For more information, see Modify the basic information of a RAM user.

  2. To create a RAM user and manage permissions manually, see Create a RAM user, Manage RAM user permissions, and Remove permissions from a RAM user.

Set an account alias (recommended)

The default logon name for a RAM user is <UserName>@<AccountAlias>.onaliyun.com, where <AccountAlias>.onaliyun.com is the Default Domain of the Alibaba Cloud account, and <AccountAlias> is the account alias. By default, the account alias is the Account ID of the Alibaba Cloud account. We recommend that you set a memorable account alias before creating RAM users. This replaces the 16-digit Account ID and simplifies RAM user logon.

To modify the Default Domain, follow these steps:

  1. Log on to the RAM console with your Alibaba Cloud account.

  2. In the left-side navigation pane, choose Settings > Domain. Click Default Domain next to the Edit to modify it.

Note
  • Only an Alibaba Cloud account or a RAM user with RAM administrator permissions can set or modify the default domain name.

  • An account alias takes effect immediately. The logon names of all new RAM users will use this alias by default.

Step 2: Log on as the RAM user

  1. Use one of the following URLs to log on to the console as a RAM user. To avoid entering the account's Default Domain each time, use the dedicated logon URL.

    General logon URL

    Log on to the Alibaba Cloud Management Console as the newly created RAM user.

    Note

    The logon page for RAM users is different from the logon page for Alibaba Cloud accounts. For more information, see Log on to the Alibaba Cloud Management Console as a RAM user.

    Dedicated logon URL

    Get the logon URL for RAM users from the Overview page of the RAM console. This URL lets a RAM user log on without entering the account's Default Domain.

    In the Basic Information section, find the Logon URL in the format https://signin.alibabacloud.com/{default domain name}/login.htm. Click Copy Logon URL on the right.

  2. On the RAM User Logon page, enter the RAM username and click Next.

  3. Enter the password for the RAM user and click Log On.

  4. The first time you log on, you must bind a multi-factor authentication (MFA) device. For subsequent logons, you will be prompted to enter an MFA code. For more information, see Bind an MFA device for a RAM user.

  5. Reset the RAM user password: By default, a RAM user created through the Get Started wizard must reset their password upon first logon.

Step 3: Verify permissions

The Auditing Administrator you created has full permissions for CloudConfig, ActionTrail, and Log Service, and can view the status of all Alibaba Cloud resources. The following steps use ActionTrail and RAM as examples to verify the permissions.

  1. After you log on to the console as the RAM user, hover over the profile picture in the upper-right corner to view the user's information.

    The panel displays information such as the RAM user's logon email address, account ID, current identity, enterprise alias, and Alibaba Cloud account ID.

  2. Go to the ActionTrail console and try to perform an operation.

    For example, in the left-side navigation pane, choose Events > Event Query to view the event records of all services.

  3. Go to the RAM console.

    1. In the left-side navigation pane, choose Identities > Users to view the created RAM users.

    2. Repeat the steps in Create a RAM user. You will receive an access denied error.

Obtain the logon name of the Alibaba Cloud account

If you need to obtain the complete logon name of the Alibaba Cloud account, for example, for cross-account operations, contacting the account administrator, or filling in application forms, use one of the following methods.

Method 1: Use the Account Center

  1. Log on to the Alibaba Cloud Management Console as a RAM user.

  2. Go to the Account Center page: https://myaccount.console.alibabacloud.com/overview.

  3. In the Account Information section, view the value of the Logon Name field. The value displays the logon name of the Alibaba Cloud account. Part of the logon name is masked.

Important

To access the Billing console page, the RAM user must be granted the AliyunBSSReadOnlyAccess permission policy. Otherwise, an access denied error is returned.

Method 2: Use the Billing console

  1. Log on to the Alibaba Cloud Management Console as a RAM user.

  2. Go to the Billing console page: https://billing-cost.console.alibabacloud.com/fortune/billing-account.

  3. In the Basic Information section, view the Account Name field. This field displays the complete logon name of the Alibaba Cloud account.

Troubleshoot common permission issues

If a RAM user encounters an access denied error when accessing a cloud resource, see How do I troubleshoot an access denied error?.

Related topics

For detailed instructions, see the following topics: