All Products
Search
Document Center

ApsaraVideo Media Processing:Create a RAM user and grant permissions

Last Updated:Sep 15, 2026

Create a Resource Access Management (RAM) user and grant permissions to the user. This lets you assign different permissions to different users to access your resources. Using RAM users helps you avoid security risks caused by leaked AccessKey pairs or logon passwords. To use ApsaraVideo Media Processing (MPS), a RAM user requires permissions for the following services: ApsaraVideo Media Processing (MPS), Object Storage Service (OSS), Resource Access Management (RAM), Alibaba Cloud CDN (CDN), and Simple Message Queue (formerly MNS). This topic describes how to create a RAM user and grant the required permissions to use MPS.

Note

If you receive the error message User not authorized to operate on the specified resource when you use MPS, check whether your RAM user has full control permissions for MPS. If not, grant the required permissions as described in this topic.

Procedure

  1. Log on to the RAM console by using an Alibaba Cloud account or a RAM user who has administrative rights.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, click Create User. 

  4. In the User Account Information section of the Create User page, configure the following parameters:

    • Logon Name: The logon name can be up to 64 characters in length, and can contain letters, digits, periods (.), hyphens (-), and underscores (_). 

    • Display Name: The display name can be up to 128 characters in length. 

    • Tag: Click the edit icon and enter a tag key and a tag value. You can add one or more tags to the RAM user. This way, you can manage the RAM user based on the tags. 

    Note

    You can click Add User to create multiple RAM users at a time.

  5. For Access Mode, select Access with permanent AccessKey.

  6. Click OK and complete the phone verification. The system automatically generates an AccessKey for the RAM user.

  7. In the Actions column, click Copy to save the user information, such as the logon name, logon password, and AccessKey.

    Important

    Make sure to save the logon password and AccessKey information (AccessKey ID and AccessKey secret). You cannot retrieve this information later.

  8. Return to the user list. In the Actions column of the new RAM user, click Add Permissions.

  9. In the Add Permissions panel, configure the authorization information.

    1. Select the scope of the authorization.

      Type

      Description

      Entire Alibaba Cloud Account

      The permissions take effect within the current Alibaba Cloud account.

      Specify a resource group

      The permissions take effect within the specified resource group.

    2. Enter the principal.

      The principal is the RAM user to whom you want to grant permissions.

    3. Select an access policy. For more information about the services that require authorization and the supported access policies, see Access policy details.

      • Use a system policy

        Enter the policy name in the search box and click the name in the search results to select it.

      • Use a custom policy

        A custom policy allows for more fine-grained permission management. You must create a custom policy before you can select it. For more information, see Create a custom policy.

  1. Click Confirm New Authorization.

Access policy details

To use MPS, you must grant permissions for MPS and OSS. You can also grant permissions for Simple Message Queue (formerly MNS) and Alibaba Cloud CDN. You must use a system policy to grant permissions for MPS. For other services, you can use a system policy or a custom policy.

Required products

Description

Required

System policy

Custom policy

ApsaraVideo Media Processing (MPS)

To use MPS, you must grant all permissions for MPS.

Yes

Full read and write permissions for MPS: AliyunMTSFullAccess

Not supported

Object Storage Service (OSS)

To use MPS, you must grant read and write permissions for OSS.

Yes

Full read and write permissions for OSS: AliyunOSSFullAccess

Supported. Create the policy first, and then grant the permissions.

Simple Message Queue (formerly MNS)

If you use Simple Message Queue (formerly MNS) to subscribe to tracking tasks, you must grant permissions for MNS.

No, optional

Full read and write permissions for MNS: AliyunMNSFullAccess

CDN Playback Acceleration

If you use MPS to configure CDN for accelerated playback, you must grant permissions for CDN.

No, optional

Full read and write permissions for CDN: AliyunCDNFullAccess

Create a custom policy

  1. Log on to the RAM console with your Alibaba Cloud account.

  2. In the navigation pane on the left, choose Permission Management > Access Policies.

  3. Click Create Policy and select the Script Editor tab.

  4. Configure the access policy. Enter the policy content, and then click OK.

    Note

    You can import a system policy or copy the required policy code from the examples below into the code box.

  1. Enter basic information such as the Name and Note.

  2. Click OK to create the custom policy.

Example: Restrict access to MPS by IP address and time period

  • The RAM user can access MPS only from the 192.0.2.0/24 and 203.0.113.2 IP addresses.

  • The RAM user can access MPS only before 17:00 on August 12, 2019 (UTC+8).

{
  "Version": "1",
    "Statement": [{
      "Effect": "Allow",
      "Action": [
        "mts:*",
        "mts-inner:*"
      ],
      "Resource": "*",
      "Condition": {
        "NotIpAddress": {
          "acs:SourceIp": [
            "192.0.2.0/24",
            "203.0.113.2"
          ]},
        "DateLessThan": {
          "acs:CurrentTime": "2019-08-12T17:00:00+08:00"
       }
     }
  ]
}

Example: OSS custom policy

  • Grants all permissions on the specified input and output buckets.

  • Grants the permission to view the bucket list.

{    
  "Version": "1",
    "Statement": [{
      "Effect": "Allow",
      "Action": [
        "oss:ListBuckets"
      ],
      "Resource": "*"
    }, {
      "Effect": "Allow",
      "Action": [
        "oss:*"
      ],
      "Resource": [
        "acs:oss:*:*:$InputBucket",
        "acs:oss:*:*:$InputBucket/*",
        "acs:oss:*:*:$OutputBucket",
        "acs:oss:*:*:$OutputBucket/*
      ]
    }
  ]
}

Parameter description:

Parameter

Description

oss:ListBuckets

This is a required permission for a RAM user to operate OSS with a visualization tool. After logging on, the RAM user can see the list of all buckets.

However, the user can only operate the $InputBucket and $OutputBucket buckets that are granted permissions. This permission can only be granted for all buckets, not for a specific bucket.

oss:*

Represents all OSS permissions. You can replace it with more specific operation permissions as needed.

"oss:GetObject",

"oss:PutObject",

"oss:GetObjectAcl",

"oss:PutObjectAcl",

"oss:AbortMultipartUpload",

"oss:ListParts",

"oss:RestoreObject",

"oss:GetVodPlaylist",

"oss:PostVodPlaylist",

"oss:PublishRtmpStream",

"oss:ListObjectVersions",

"oss:GetObjectVersion",

"oss:GetObjectVersionAcl",

"oss:RestoreObjectVersion"

$InputBucket

Replace this with the bucket where the MPS input files are located.

$OutputBucket

Replace this with the bucket where the MPS output files are located.

For more information, see Common examples of bucket policies.

Example: RAM authorization policy

Grants the permission to view roles.

{
  "Version": "1",
    "Statement": [{
      "Effect": "Allow",
      "Action": [
        "ram:ListPoliciesForRole"
      ],
      "Resource": "*"
    }
  ]
}

Example: MNS custom policy

  • Grants the permission to view all queue and topic lists.

  • Grants full read and write permissions only for the specified $QueueName and $TopicName.

{
  "Version": "1",
    "Statement": [{
      "Effect":"Allow",
      "Action":[
        "mns:ListQueue",
        "mns:ListTopic",
        "mns:GetQueueAttributes",
        "mns:GetTopicAttributes"
      ],
      "Resource":"acs:mns:*:*:*"
    }, {
      "Effect": "Allow",
      "Action": "mns:*",
      "Resource": [
        "acs:mns:$Region:$Uid:/queues/$QueueName", 
        "acs:mns:$Region:$Uid:/topics/$TopicName"
      ]
    }
  ]
}

Parameter description:

Parameter

Description

$QueueName

The name of the MNS queue to be attached to the MPS queue or workflow.

$TopicName

The name of the MNS notification subject and the name of the queue to attach to the pipeline or workflow.

For more information, see Authorization policies and examples.

Example: CDN authorization policy

  • Grants the permission to view all CDN-accelerated domain names.

  • Grants full read and write permissions only for the specified CDN-accelerated domain name $DomainName.

{
  "Version": "1",
  "Statement": [{
        "Effect": "Allow",
        "Action": "cdn:*",
        "Resource": "acs:cdn:*:$Uid:domain/$DomainName"
        },{
        "Effect": "Allow",
        "Action": "cdn:Describe*",
        "Resource": "*"
      }
  ]
}

Parameter description:

Parameter

Description

$DomainName

The CDN-accelerated domain name.

What to do next

After you create a RAM user and grant permissions, you can log on to the console as the RAM user. For more information, see Log on to the Alibaba Cloud Management Console as a RAM user.