All Products
Search
Document Center

Resource Access Management:Restrict user access by time period

Last Updated:Sep 17, 2026

You can restrict when specific RAM users can access your Alibaba Cloud resources by configuring time-based conditions in RAM custom policies.

Prerequisites

  • An Alibaba Cloud account, or a RAM user that has RAM management permissions. You use this identity to log on to the RAM console and complete the steps in this topic.

Scenario

Enterprise A runs its business on many Alibaba Cloud resources, such as ECS instances, RDS instances, SLB instances, and OSS buckets. To protect its business and data security, the enterprise wants its users to access Alibaba Cloud only during working hours instead of at any time.

To achieve this, you create a custom policy that contains a time-based condition, create a RAM user if one does not already exist, and then attach the policy to the RAM user. The RAM user can then access the specified Alibaba Cloud resources only during the specified time period.

Step 1: Create a custom policy

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Permissions > Policies.

  3. On the Policies page, click Create Policy.

  4. On the Create Policy page, click the JSON Editor tab.

    The page displays a JSON editor. The default policy template includes a Version element (set to "1") and a Statement array. Each statement includes Effect (defaults to "Allow"), Action, Resource, and Condition elements. You must populate the Action and Resource elements.

  5. Enter the policy document.

    The following sample policy allows a RAM user to access ECS only before 17:00:00 on August 12, 2019 (UTC+8). This time value is a sample. Replace it with the time period during which your enterprise allows access. The policy allows access only before the specified point in time. It uses the DateLessThan operator to set acs:CurrentTime in the Condition element to 2019-08-12T17:00:00+08:00.

    {
      "Statement": [
        {
          "Action": "ecs:*",
          "Effect": "Allow",
          "Resource": "*",
          "Condition": {
              "DateLessThan": {
                  "acs:CurrentTime": "2019-08-12T17:00:00+08:00"
              }
          }
        }
      ],
      "Version": "1"
    }
    Note

    The Condition element applies only to the operations described by the current policy. You can replace 2019-08-12T17:00:00+08:00 with the time period during which your enterprise allows access.

  6. At the top of the page, click Optimize, and then click Perform to perform advanced optimization on the policy.

    The advanced policy optimization feature performs the following tasks:

    • Splits resources or conditions for incompatible actions.

    • Narrows the scope of resources.

    • Removes duplicate statements or merges statements.

  7. In the Create Policy dialog box, click OK.

  8. In the Create Policy dialog box, enter a policy name and Description, and then click OK.

Step 2: Create a RAM user

  1. Log on to the RAM console by using your Alibaba Cloud account (root account) or as a RAM administrator.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, click Create User.

  4. On the Create User page, in the User Account Information section, configure the basic information of the user.

    • Logon Name: The logon name can contain letters, digits, periods (.), hyphens (-), and underscores (_), and can be up to 64 characters in length.

    • Display Name: The display name can be up to 128 characters in length.

    • Tag: Click edit, and then enter a tag key and a tag value. Tags simplify tag-based management of your RAM users.

  5. In the Access Mode section, select an access mode and configure the corresponding parameters.

    For account security, select only one access mode for each RAM user. This separates human users from application users.

    • Console Access

      If the RAM user represents a human user, enable console access so that the user can access Alibaba Cloud by using a username and a logon password. Configure the following parameters:

      • Console logon password: Select automatic password generation or specify a custom password. A custom logon password must meet the password complexity requirements. For more information, see Set a password policy for RAM users.

      • Password reset policy: Specify whether the RAM user must reset the password at the next logon.

      • Multi-factor authentication (MFA) policy: Specify whether to enable MFA for the current RAM user. After you enable MFA, you must also bind an MFA device. For more information, see Bind an MFA device.

    • Permanent AccessKey

      If the RAM user represents an application, you can use a permanent AccessKey pair to access Alibaba Cloud. After you enable this access mode, the system automatically generates an AccessKey ID and an AccessKey secret for the RAM user. For more information, see Create an AccessKey pair.

      • The AccessKey secret is displayed only at creation and cannot be viewed later. Keep it secure.

      • An AccessKey pair is a long-term credential for programmatic access. A leaked AccessKey pair threatens the security of all resources under the account. To reduce the risk of credential leaks, use a Security Token Service token (temporary credentials) instead. For more information, see Best practices for using access credentials to call Alibaba Cloud APIs.

  6. Click OK

Step 3: Grant permissions to the RAM user

Attach the custom policy created in Step 1 to the RAM user created in Step 2.

Console

The RAM console offers two entry points, both supporting single and batch authorization:

  • Users page: The principal is auto-selected based on the users you choose. Best for user-centric workflows.

  • Grants page: You manually select principals and can view all authorization records across your account. Best for permission-centric workflows.

Note

Tip: For large-scale management, add RAM users with identical responsibilities to a user group, then grant permissions to the group. Navigate to Identities > User Groups to manage groups.

From the Users page

  1. Log on to the RAM console.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, find the target RAM user and click Actions column > Attach Policy.

    You can also select multiple RAM users and click Attach Policy below the user list for batch authorization.

  4. In the Grant Permission panel, configure the following settings:

    • Resource scope:

      • Account level: Permissions apply to all resources in your Alibaba Cloud account.

      • Resource group level: Permissions apply only within the specified resource group. After logging on, the RAM user must switch to the authorized resource group in the top navigation bar.

        Note
        1. The system marks high-risk system policies (such as AdministratorAccess and AliyunRAMFullAccess) with a warning indicator. These policies typically grant full control over all cloud resources or full management of RAM. Grant these policies with caution.

        2. For resource group authorization examples, see Control RAM user access to specific ECS instances.

    • Principal:

      The principal is the RAM user receiving permissions. From the Users page, the system auto-selects the current user. From the Grants page, you must manually select the user. Batch selection is supported.

    • Permission policy:

      • System policy: Search and select. Filter by product name (e.g., ECS, OSS), access level (e.g., ReadOnly, FullAccess), or full policy name. For example, to grant permissions for financial management (expenses and costs), search for BSS to find AliyunBSSFullAccess (full access to Billing and Cost Management) and other finance-related policies.

        The following table lists system policy names for commonly requested Alibaba Cloud products to help you quickly find the right policy.

        Product

        System policy name

        Access level

        Billing and cost management (finance)

        AliyunBSSFullAccess

        Full access

        Cloud Monitor

        AliyunCloudMonitorReadOnlyAccess

        Read-only

        China Gateway (Website Builder)

        AliyunWebsiteBuildFullAccess

        Full access

        Alibaba Cloud DevOps

        AliyunYunxiaoFullAccess

        Full access

        Model Studio (Bailian)

        AliyunBailianFullAccess

        Full access

        Alibaba Cloud DNS

        AliyunDNSFullAccess

        Full access

        SSL Certificates Service

        AliyunYundunCertFullAccess

        Full access

        Cloud Phone

        AliyunECDFullAccess

        Full access

        Support Center

        AliyunSupportFullAccess

        Full access

        Resource Center

        AliyunResourceCenterFullAccess

        Full access

        AgentBay

        AliyunAgentBayFullAccess

        Full access

        Security Center

        AliyunYundunSASFullAccess

        Full access

        If you cannot find the policy for your target product, see the System policy reference for the complete list, or create a custom policy for fine-grained access control.

      • Custom policy: You must Create a custom policy before you can grant it.

      • Pagination limit for select all: The policy list is paginated. Selecting all applies only to the current page. After you switch pages, previously selected policies remain in the selected list, but policies on the new page are not automatically selected; you must select them page by page.

      • Quickly grant administrator permissions: To grant administrator permissions, search for AdministratorAccess in the search box and select it directly, instead of selecting policies page by page. Selecting this policy triggers a high-risk authorization warning.

    • (Optional) Description: Enter the authorization reason or scenario for audit purposes.

    • Click Confirm.

  5. Review the authorization result and click Close.

From the Grants page

  1. Log on to the RAM console.

  2. In the left-side navigation pane, choose Permissions > Grants.

  3. On the Grants page, click Grant Permission.

  4. In the Grant Permission panel, select the principal and configure the same settings as described above.

  5. Review the authorization result and click Close.

Note

RAM users created through the Quick Start feature on the RAM console Overview page are automatically granted the corresponding system policy based on the selected scenario, with no manual authorization required:

  • Super user: Automatically granted the PowerUserAccess policy. This user can manage cloud services and resources, but cannot manage RAM identities and their permissions, resource directories, or billing accounts.

  • Account administrator: Automatically granted the AdministratorAccess policy. This user can manage all Alibaba Cloud resources, including RAM identities and permissions.

Use these options only when super administrator privileges are truly required. For routine operations, follow the principle of least privilege and grant only the permissions required for the specific task.

OpenAPI

Grant a custom policy

  1. Call CreatePolicy to create a custom policy. For policy syntax, see Permission policy elements and Overview of sample policies.

  2. Call AttachPolicyToUser to grant the policy at the account level (set PolicyType to Custom).

    Alternatively, call AttachPolicy to grant the policy at the resource group level.

Grant a system policy