By default, Resource Access Management (RAM) users cannot create Global Accelerator (GA) resources, or access or manage GA resources created by Alibaba Cloud accounts. If you want to access or manage GA resources as a RAM user, you must first grant the required permissions to the RAM user.

Prerequisites

A RAM user is created. For more information, see Create a RAM user.

Background information

You can attach the following policies to a RAM user:
  • AliyunGlobalAccelerationReadOnlyAccess: grants the RAM user read-only permissions on GA.
  • AliyunGlobalAccelerationFullAccess: grants the RAM user full permissions on GA.

Procedure

  1. Log on to the RAM console by using your Alibaba Cloud account.
  2. In the left-side navigation pane, choose Identities > Users.
  3. On the Users page, find the RAM user to which you want to attach the custom policy, and click Add Permissions in the Actions column.
  4. In the Add Permissions panel, grant permissions to the RAM user.
    1. Select the authorization scope.
      • Alibaba Cloud Account: The authorization takes effect on the current Alibaba Cloud account.
      • Specific Resource Group: The authorization takes effect in a specific resource group.
        Note If you select Specific Resource Group for Authorized Scope, make sure that the required cloud service supports resource groups. For more information, see Services that work with Resource Group.
    2. Specify the principal.
      The principal is the RAM user to which you want to grant permissions. By default, the current RAM user is specified. You can also specify another RAM user.
    3. Select policies.
      Note You can attach a maximum of five policies to a RAM user at a time. If you want to attach more than five policies to a RAM user, perform the operation multiple times.
  5. Click OK.
  6. Click Complete.