All Products
Search
Document Center

Resource Access Management:Create a custom policy

Last Updated:Sep 28, 2026

You can create a custom policy to implement fine-grained permission management.

Creation methods

  • Using the visual editor

    RAM provides a WYSIWYG visual editor. You can generate a custom policy by selecting an effect, service, action, resource, and condition. A built-in intelligent validation feature helps ensure that your policy is valid and effective. This method is straightforward.

  • Using the script editor

    RAM provides a JSON script editor. You must write the custom policy according to the policy syntax and structure. This method offers greater flexibility and is a good choice if you are familiar with policy syntax.

  • By importing a policy

    • Import a policy template: RAM provides policy templates for common scenarios, such as for system administrators, finance staff, and network administrators. You can import a suitable policy template and make minor modifications to quickly create a custom policy.

    • Import a system policy: You can import a system policy and modify it to fit your business needs. This is a convenient and fast way to create a custom policy from a standardized template.

Using the visual editor

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Permissions > Policies.

  3. On the Policies page, click Create Policy.

  4. On the Create Policy page, click the Visual Editor tab.

    The visual editor displays a statement form that includes the following fields: Effect (Required, can be set to Allow or Deny, default: Allow), Service (Required), Action (Required), Resource (Required), and Condition (Optional). You must select a service before you can configure Action, Resource, and Condition. At the bottom of the page, you can click Add Statement to add more statements.

  5. Configure the policy.

    To learn more about the basic elements of a policy, see Permission policy elements.

    1. In the Effect section, select Allow or Deny.

    2. In the Service section, select a service.

      Note

      The console displays the services that support the visual editor.

    3. In the Action section, select All action(s) or Select action(s).

      The system automatically lists the available actions based on the service that you selected in the previous step. If you select Select action(s), you must then select the specific actions.

    4. In the Resources section, select All Resources or Specified resource(s).

      The system automatically lists the available resource types based on the actions that you selected. If you select Specified resource(s), you must click Add Resource to specify the ARNs. You can use the Match All feature to quickly select all resources for a configuration item.

      Note

      The UI marks the ARNs for associated actions as Required. Specify these ARNs to ensure that the policy works correctly.

    5. In the Condition section, click Add Condition to configure conditions.

      Conditions include Alibaba Cloud common conditions and service-specific conditions. The system automatically lists the available conditions based on the service and actions that you configured. Simply select a condition key and configure its value.

    6. Click Add Statement and repeat the preceding steps to configure multiple statements.

  6. At the top of the page, click Optimize, and then click Perform to perform advanced optimization on the policy.

    The advanced policy optimization feature performs the following tasks:

    • Splits resources or conditions for incompatible actions.

    • Narrows the scope of resources.

    • Removes duplicate statements or merges statements.

  7. On the Create Policy page, click OK.

  8. In the Create Policy dialog box, enter a Policy Name and Description, and then click OK.

Using the script editor

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Permissions > Policies.

  3. On the Policies page, click Create Policy.

  4. On the Create Policy page, click the JSON Editor tab.

    The page displays a JSON editor. The default policy template includes a Version element (set to "1") and a Statement array. Each statement includes Effect (defaults to "Allow"), Action, Resource, and Condition elements. You must populate the Action and Resource elements.

  5. Enter the policy content.

    To learn more about the policy syntax and structure, see Policy structure and syntax.

  6. At the top of the page, click Optimize, and then click Perform to perform advanced optimization on the policy.

    The advanced policy optimization feature performs the following tasks:

    • Splits resources or conditions for incompatible actions.

    • Narrows the scope of resources.

    • Removes duplicate statements or merges statements.

  7. On the Create Policy page, click OK.

  8. In the Create Policy dialog box, enter a Policy Name and Description, and then click OK.

Common custom policy examples

The following examples show the common scenarios and corresponding policy JSON for configuring custom policies in JSON Editor mode, helping you write policies quickly.

Scenario 1: Grant RAM user management permissions (account-level)

RAM user management APIs (such as ram:CreateUser, ram:CreateAccessKey, and ram:ListUsers) are account-level operations. The Resource element must be set to "*", and when you grant the permission, you must set the authorization scope to Entire Alibaba Cloud Account. These operations cannot be restricted to a resource group.

Policy example: allows creating RAM users and AccessKeys.


{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ram:CreateUser",
        "ram:CreateAccessKey",
        "ram:ListUsers"
      ],
      "Resource": ["*"]
    }
  ]
}
Important

If you set the authorization scope of this policy to a specific resource group, the policy does not take effect. RAM user management operations support only the authorization scope of Entire Alibaba Cloud Account.

Scenario 2: Allow RAM users to change only their own passwords

To allow a RAM user to change only their own logon password, grant the ram:ChangePassword permission. Do not grant AliyunRAMFullAccess (full RAM access permissions), because excessive permissions pose security risks.

Policy example: allows changing only their own password.


{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ram:ChangePassword"
      ],
      "Resource": ["*"]
    }
  ]
}

Scenario 3: Grant read-only access to a specific resource (using an ECS instance as an example)

To allow a RAM user to view only a specific ECS instance, specify the ARN of the instance in the Resource element. The ARN format is acs:ecs:{region}:{account-id}:instance/{instance-id}. Note that instance must be followed by a forward slash /.

Policy example: allows viewing only the specified ECS instance.


{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ecs:DescribeInstances",
        "ecs:DescribeInstanceAttribute",
        "ecs:DescribeInstanceStatus"
      ],
      "Resource": [
        "acs:ecs:*:*:instance/i-bp1xxxxxxxxxxxxxxxxx"
      ]
    }
  ]
}
Note

Replace i-bp1xxxxxxxxxxxxxxxxx with the actual ECS instance ID. To grant access to multiple instances, add multiple ARNs to the Resource array, separated by commas.

Scenario 4: Fine-grained authorization for Simple Log Service (SLS)

Query operations in Simple Log Service require ARNs at the project and Logstore levels. If SDK calls still return permission denied errors, add the log:GetProject and log:GetLogStore permissions.

Policy example: allows querying the log data of a specific Logstore.


{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "log:GetLogStoreLogs",
        "log:CreateStoreView",
        "log:GetProject",
        "log:GetLogStore"
      ],
      "Resource": [
        "acs:log:*:*:project/exampleproject",
        "acs:log:*:*:project/exampleproject/logstore/examplelogstore"
      ]
    }
  ]
}
Note

Replace exampleproject and examplelogstore with the actual project name and Logstore name.

Scenario 5: Configure specific actions not supported in the visual editor

Actions of some products cannot be selected in Visual Editor mode and must be manually configured in JSON Editor mode. Common actions of this type include:

Product

Action

Description

Server Guard (Security Center)

yundun-sc:DescribeCdnIpList

Queries the CDN IP list

Milvus

CreateConnection, DbmConnect, and more

Permissions required to log on to the Milvus console

Scenario 6: Minimum permissions for ECS deployment

Creating an ECS instance involves a combination of actions across services. The least-privilege policy must include both instance operation permissions and query permissions for the network and security groups.

Policy example: the minimum permissions required to create and deploy an ECS instance.


{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ecs:RunInstances",
        "ecs:DescribeInstances",
        "vpc:DescribeVpcs",
        "vpc:DescribeVSwitches",
        "ecs:DescribeSecurityGroups"
      ],
      "Resource": ["*"]
    }
  ]
}

Action descriptions: ecs:RunInstances (creates and starts an instance), ecs:DescribeInstances (queries instance information), vpc:DescribeVpcs and vpc:DescribeVSwitches (let you select the VPC and vSwitch when creating the instance), ecs:DescribeSecurityGroups (selects the security group).

Scenario 7: Minimum permissions for VPC network configuration

The minimum permission policy required to create a virtual private cloud (VPC) and a vSwitch is as follows.

Policy example: the minimum permissions required to create a VPC and a vSwitch.


{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "vpc:CreateVpc",
        "vpc:CreateVSwitch",
        "vpc:CreateSecurityGroup",
        "vpc:DescribeVpcs",
        "vpc:DescribeVSwitches"
      ],
      "Resource": ["*"]
    }
  ]
}

Action descriptions: vpc:CreateVpc (creates a VPC), vpc:CreateVSwitch (creates a vSwitch), vpc:CreateSecurityGroup (creates a security group), vpc:DescribeVpcs and vpc:DescribeVSwitches (query existing network resources).

Troubleshoot permission denied errors

When a RAM user calls an API and receives an AccessForbidden error, or the console displays a permission denied message, troubleshoot the issue as follows:

  1. Use the API Troubleshoot tool to locate the missing permissions

    Enter the RequestID returned with the error into the Alibaba Cloud API Troubleshoot tool. The tool displays the specific missing AuthAction, so you can add the required permissions as prompted.

  2. Verify that the authorization scope matches

    For account-level operations (such as ram:CreateUser), the authorization scope must be Entire Alibaba Cloud Account. For resource group-aware APIs, ensure that the policy is granted to the correct resource group or Entire Alibaba Cloud Account. If the authorization scope does not match the Resource definition in the policy, the permissions do not take effect.

  3. Check for implicit dependency permissions

    In addition to the primary action, some operations require associated basic permissions such as Describe, List, or Connect to work correctly. For example:

    • Simple Log Service (SLS): in addition to log:GetLogStoreLogs for querying logs, you also need the log:GetProject and log:GetLogStore permissions.

    • Milvus: in addition to the primary operation permissions for logging on to the console, you also need connection permissions such as CreateConnection and DbmConnect.

    We recommend that you refer to the RAM authorization documentation of the corresponding Alibaba Cloud service to add the required permissions.

Optimize an over-size policy

The JSON content of a custom policy cannot exceed 6,144 bytes. When this limit is exceeded, the CreatePolicy operation returns an InvalidParameter.PolicyDocument.Length error (with the message "The policy document size is limited to 6144 bytes"). You can use the following methods to reduce the policy length.

Split a policy by function

Split a large policy that covers multiple functions into separate policies, and attach each one to a different RAM user or user group. For example, split read and write operations into two policies:

  • Read-only policy: {"Action": ["oss:Get*", "oss:List*"]}

  • Write policy: {"Action": ["oss:Put*", "oss:Delete*"]}

Split a policy by resource

Split policies by resource. For example, separate the permissions for different OSS buckets into different policies, so that each policy grants permissions only for a specific bucket. This avoids having a single policy manage too many resources.

Usage notes

  • When you configure a policy in the visual editor, avoid selecting all actions. Select the least-privileged set of actions first.

  • After you split a policy, you must grant each resulting policy to RAM users or user groups separately, which increases management complexity.

  • Wildcards may cause over-authorization. Carefully review the permission scope before using them.

  • A policy takes effect immediately after it is granted. No waiting is required.

By importing a policy

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Permissions > Policies.

  3. On the Policies page, click Create Policy.

  4. On the Create Policy page, click Import Policy.

  5. In the Import Policy dialog box, from the drop-down list in the upper-right corner, select a policy template or System Policy, and then import the policy.

    1. Select a policy template or a system policy.

    2. For some policy templates, you must configure parameters based on your business requirements.

    3. Select an overwrite rule for the imported policy.

      By default, the newly imported policy content completely overwrites the existing content. You can also select Do NOT overwrite but append new statements. to append the newly imported policy content to the end of the existing content.

    4. Click Import.

  6. In the visual editor or script editor, view and modify the imported policy content.

  7. At the top of the page, click Optimize, and then click Perform to perform advanced optimization on the policy.

    The advanced policy optimization feature performs the following tasks:

    • Splits resources or conditions for incompatible actions.

    • Narrows the scope of resources.

    • Removes duplicate statements or merges statements.

  8. On the Create Policy page, click OK.

  9. In the Create Policy dialog box, enter a Policy Name and Description, and then click OK.

FAQ

Why can't I find certain permissions in the visual editor, or why does saving a policy fail?

This issue can occur for the following reasons:

  • Some actions are not updated in the visual list: some newly released or low-level APIs may not yet be synced to the action list in Visual Editor mode, or a wildcard (such as swas-open:*) may have parsing conflicts under specific resource restrictions. We recommend that you switch to JSON Editor mode and enter the action manually.

  • The action name is misspelled: some API action names have singular and plural differences (for example, the ECS operation for reinitializing a disk is ecs:ReInitDisks rather than ecs:ReInitDisk). Verify the exact action name in the API documentation of the corresponding Alibaba Cloud service.

  • The system policy is not synced: if you cannot find a specific system policy (such as AliyunAccountCenterFullAccess), you can view the official JSON content of that system policy and create a custom policy with the same effect in JSON Editor mode.

  • JSON format validation failed: check whether the JSON syntax is correct. Pay special attention to the following common mistakes:

    • Resource cannot be defined more than once. To specify multiple resources, list them in a single array, separated by commas.

    • The ARN format must comply with the following pattern: acs:<service>:<region>:<account-id>:<resource-type>/<resource-id>.

Why can't I access the console or perform operations after granting FullAccess or a custom policy?

This issue can occur for the following reasons:

  • Console access requires additional basic permissions: in addition to business permissions, some product consoles (such as ICP filing value-added services) also require basic console access permissions such as PowerUserAccess. A business-specific FullAccess policy alone may not be sufficient to load the console page. Refer to the product documentation to confirm the complete combination of permissions required for console access.

  • The authorization scope does not match the Resource in the policy: the authorization scope that you select when granting the permission (Entire Alibaba Cloud Account or a specific resource group) must be consistent with the Resource definition in the policy. For example, instance-level operations such as OceanBase require the authorization scope to be Entire Alibaba Cloud Account, with the specific instance ARN defined in the policy.

  • Policy conflict or Deny override: check whether a Deny statement overrides an Allow, or whether a conflict exists between your custom policies and system policies. The policy evaluation logic of RAM is: explicit Deny > Allow > default Deny. For complex scenarios (such as MQTT public network access), if a custom policy does not take effect, we recommend that you first use the officially recommended system policy (such as AliyunMQFullAccess) to verify connectivity, and then refine the permissions step by step.