By default, Resource Access Management (RAM) users cannot create Global Accelerator (GA) resources, or access or manage GA resources created by Alibaba Cloud accounts. If you want to access or manage GA resources as a RAM user, you must first grant the required permissions to the RAM user.


A RAM user is created. For more information, see Create a RAM user.


  1. Log on to the RAM console with your Alibaba Cloud account.
  2. In the left-side navigation pane, choose Identities > Users.
  3. On the Users page, find the RAM user and click Add Permissions in the Actions column.
  4. In the Add Permissions panel, set the following parameters and click OK.
    Parameter Description
    Authorized Scope The authorization scope. Valid values:
    • Alibaba Cloud Account: The authorization takes effect on the current Alibaba Cloud account.
    • Specific Resource Group: The authorization takes effect on a specified resource group.
    Principal The system automatically specifies the RAM user created in Step 3 as the principal.
    Select Policy Select System Policy and then select permission policies that you want to attach to the RAM user.
    You can attach the following system policies of GA to a RAM user:
    • AliyunGlobalAccelerationReadOnlyAccess: Grants the RAM user read-only permissions on GA.
    • AliyunGlobalAccelerationFullAccess: Grants the RAM user full permissions on GA.
  5. Confirm the authorization scope and permission policies and click Complete.