You can restrict when specific RAM users can access your Alibaba Cloud resources by configuring time-based conditions in RAM custom policies.
Prerequisites
An Alibaba Cloud account, or a RAM user that has RAM management permissions. You use this identity to log on to the RAM console and complete the steps in this topic.
Scenario
Enterprise A runs its business on many Alibaba Cloud resources, such as ECS instances, RDS instances, SLB instances, and OSS buckets. To protect its business and data security, the enterprise wants its users to access Alibaba Cloud only during working hours instead of at any time.
To achieve this, you create a custom policy that contains a time-based condition, create a RAM user if one does not already exist, and then attach the policy to the RAM user. The RAM user can then access the specified Alibaba Cloud resources only during the specified time period.
Step 1: Create a custom policy
Log on to the RAM console as a RAM administrator.
In the left-side navigation pane, choose .
On the Policies page, click Create Policy.
On the Create Policy page, click the JSON Editor tab.
The page displays a JSON editor. The default policy template includes a
Versionelement (set to"1") and aStatementarray. Each statement includesEffect(defaults to"Allow"),Action,Resource, andConditionelements. You must populate theActionandResourceelements.Enter the policy document.
The following sample policy allows a RAM user to access ECS only before 17:00:00 on August 12, 2019 (UTC+8). This time value is a sample. Replace it with the time period during which your enterprise allows access. The policy allows access only before the specified point in time. It uses the
DateLessThanoperator to setacs:CurrentTimein theConditionelement to2019-08-12T17:00:00+08:00.{ "Statement": [ { "Action": "ecs:*", "Effect": "Allow", "Resource": "*", "Condition": { "DateLessThan": { "acs:CurrentTime": "2019-08-12T17:00:00+08:00" } } } ], "Version": "1" }NoteThe
Conditionelement applies only to the operations described by the current policy. You can replace2019-08-12T17:00:00+08:00with the time period during which your enterprise allows access.At the top of the page, click Optimize, and then click Perform to perform advanced optimization on the policy.
The advanced policy optimization feature performs the following tasks:
Splits resources or conditions for incompatible actions.
Narrows the scope of resources.
Removes duplicate statements or merges statements.
In the Create Policy dialog box, click OK.
In the Create Policy dialog box, enter a policy name and Description, and then click OK.
Step 2: Create a RAM user
Log on to the RAM console by using your Alibaba Cloud account (root account) or as a RAM administrator.
In the left-side navigation pane, choose Identities > Users.
On the Users page, click Create User.
On the Create User page, in the User Account Information section, configure the basic information of the user.
Logon Name: The logon name can contain letters, digits, periods (.), hyphens (-), and underscores (_), and can be up to 64 characters in length.
Display Name: The display name can be up to 128 characters in length.
Tag: Click
, and then enter a tag key and a tag value. Tags simplify tag-based management of your RAM users.
In the Access Mode section, select an access mode and configure the corresponding parameters.
For account security, select only one access mode for each RAM user. This separates human users from application users.
Console Access
If the RAM user represents a human user, enable console access so that the user can access Alibaba Cloud by using a username and a logon password. Configure the following parameters:
Console logon password: Select automatic password generation or specify a custom password. A custom logon password must meet the password complexity requirements. For more information, see Set a password policy for RAM users.
Password reset policy: Specify whether the RAM user must reset the password at the next logon.
Multi-factor authentication (MFA) policy: Specify whether to enable MFA for the current RAM user. After you enable MFA, you must also bind an MFA device. For more information, see Bind an MFA device.
Permanent AccessKey
If the RAM user represents an application, you can use a permanent AccessKey pair to access Alibaba Cloud. After you enable this access mode, the system automatically generates an AccessKey ID and an AccessKey secret for the RAM user. For more information, see Create an AccessKey pair.
The AccessKey secret is displayed only at creation and cannot be viewed later. Keep it secure.
An AccessKey pair is a long-term credential for programmatic access. A leaked AccessKey pair threatens the security of all resources under the account. To reduce the risk of credential leaks, use a Security Token Service token (temporary credentials) instead. For more information, see Best practices for using access credentials to call Alibaba Cloud APIs.
Click OK
Step 3: Grant permissions to the RAM user
Attach the custom policy created in Step 1 to the RAM user created in Step 2.
Console
The RAM console offers two entry points, both supporting single and batch authorization:
-
Users page: The principal is auto-selected based on the users you choose. Best for user-centric workflows.
-
Grants page: You manually select principals and can view all authorization records across your account. Best for permission-centric workflows.
Tip: For large-scale management, add RAM users with identical responsibilities to a user group, then grant permissions to the group. Navigate to Identities > User Groups to manage groups.
From the Users page
-
Log on to the RAM console.
-
In the left-side navigation pane, choose .
-
On the Users page, find the target RAM user and click Actions column > Attach Policy.
You can also select multiple RAM users and click Attach Policy below the user list for batch authorization.
-
In the Grant Permission panel, configure the following settings:
-
Resource scope:
-
Account level: Permissions apply to all resources in your Alibaba Cloud account.
-
Resource group level: Permissions apply only within the specified resource group. After logging on, the RAM user must switch to the authorized resource group in the top navigation bar.
Note-
The system marks high-risk system policies (such as AdministratorAccess and AliyunRAMFullAccess) with a warning indicator. These policies typically grant full control over all cloud resources or full management of RAM. Grant these policies with caution.
-
For resource group authorization examples, see Control RAM user access to specific ECS instances.
-
-
-
Principal:
The principal is the RAM user receiving permissions. From the Users page, the system auto-selects the current user. From the Grants page, you must manually select the user. Batch selection is supported.
-
Permission policy:
-
System policy: Search and select. Filter by product name (e.g.,
ECS,OSS), access level (e.g.,ReadOnly,FullAccess), or full policy name. For example, to grant permissions for financial management (expenses and costs), search forBSSto findAliyunBSSFullAccess(full access to Billing and Cost Management) and other finance-related policies.The following table lists system policy names for commonly requested Alibaba Cloud products to help you quickly find the right policy.
Product
System policy name
Access level
Billing and cost management (finance)
AliyunBSSFullAccessFull access
Cloud Monitor
AliyunCloudMonitorReadOnlyAccessRead-only
China Gateway (Website Builder)
AliyunWebsiteBuildFullAccessFull access
Alibaba Cloud DevOps
AliyunYunxiaoFullAccessFull access
Model Studio (Bailian)
AliyunBailianFullAccessFull access
Alibaba Cloud DNS
AliyunDNSFullAccessFull access
SSL Certificates Service
AliyunYundunCertFullAccessFull access
Cloud Phone
AliyunECDFullAccessFull access
Support Center
AliyunSupportFullAccessFull access
Resource Center
AliyunResourceCenterFullAccessFull access
AgentBay
AliyunAgentBayFullAccessFull access
Security Center
AliyunYundunSASFullAccessFull access
If you cannot find the policy for your target product, see the System policy reference for the complete list, or create a custom policy for fine-grained access control.
-
Custom policy: You must Create a custom policy before you can grant it.
-
Pagination limit for select all: The policy list is paginated. Selecting all applies only to the current page. After you switch pages, previously selected policies remain in the selected list, but policies on the new page are not automatically selected; you must select them page by page.
-
Quickly grant administrator permissions: To grant administrator permissions, search for
AdministratorAccessin the search box and select it directly, instead of selecting policies page by page. Selecting this policy triggers a high-risk authorization warning.
-
-
(Optional) Description: Enter the authorization reason or scenario for audit purposes.
-
Click Confirm.
-
-
Review the authorization result and click Close.
From the Grants page
-
Log on to the RAM console.
-
In the left-side navigation pane, choose .
-
On the Grants page, click Grant Permission.
-
In the Grant Permission panel, select the principal and configure the same settings as described above.
-
Review the authorization result and click Close.
RAM users created through the Quick Start feature on the RAM console Overview page are automatically granted the corresponding system policy based on the selected scenario, with no manual authorization required:
-
Super user: Automatically granted the
PowerUserAccesspolicy. This user can manage cloud services and resources, but cannot manage RAM identities and their permissions, resource directories, or billing accounts. -
Account administrator: Automatically granted the
AdministratorAccesspolicy. This user can manage all Alibaba Cloud resources, including RAM identities and permissions.
Use these options only when super administrator privileges are truly required. For routine operations, follow the principle of least privilege and grant only the permissions required for the specific task.
OpenAPI
Grant a custom policy
-
Call CreatePolicy to create a custom policy. For policy syntax, see Permission policy elements and Overview of sample policies.
-
Call AttachPolicyToUser to grant the policy at the account level (set
PolicyTypetoCustom).Alternatively, call AttachPolicy to grant the policy at the resource group level.
Grant a system policy
-
Call AttachPolicyToUser to attach the system policy to the RAM user (set
PolicyTypetoSystem). For availablePolicyNamevalues, see System policy reference. -
Alternatively, call AttachPolicy to grant the policy at the resource group level.