When you grant permissions to a RAM user group, all RAM users in that group inherit those permissions. As a best practice, follow the principle of least privilege and grant only the necessary permissions.
Method 1: Grant permissions on the Groups page
-
Log on to the RAM console as a RAM administrator.
-
In the navigation pane, choose .
-
On the Groups page, find the target RAM user group and click Grant Permissions in the Actions column.
You can also select multiple RAM user groups and click Grant Permissions below the list to grant permissions to the groups in bulk.
-
In the Grant Permissions panel, configure the permission grant.
-
Select the resource scope.
-
Account: The permissions apply within the current Alibaba Cloud account.
-
Resource Group: The permissions apply within the specified resource group.
NoteFor permissions to apply to a resource group, the cloud service and resource type must support resource groups. For more information, see Cloud services that support resource groups.
-
-
Select the principal.
The principal is the RAM user group you want to grant permissions to. The system automatically selects this group.
-
Select one or more policies.
A policy is a set of permissions. You can select multiple policies.
-
System policies: These are predefined policies created and maintained by Alibaba Cloud. You can use these policies but cannot modify them. For more information, see Cloud services that support RAM.
NoteThe system automatically flags high-risk system policies (for example, AdministratorAccess and AliyunRAMFullAccess). Avoid granting unnecessary high-risk system policies.
-
Custom policies: These are policies that you create and manage. You can create, update, and delete them. For more information, see Create a custom policy.
-
-
Click OK.
-
-
Click close.
Method 2: Grant permissions on the Grants page
-
Log on to the RAM console as a RAM administrator.
-
In the navigation pane, choose .
-
On the Grants page, click Grant Permission.
-
In the Grant Permission panel, configure the permission grant.
-
Select the resource scope.
-
Account: The permissions apply within the current Alibaba Cloud account.
-
Resource Group: The permissions apply within the specified resource group.
NoteFor permissions to apply to a resource group, the cloud service and resource type must support resource groups. For more information, see Cloud services that support resource groups.
-
-
Select the principal.
The principal is the RAM user group you want to grant permissions to. You can select multiple RAM user groups.
-
Select one or more policies.
A policy is a set of permissions. You can select multiple policies.
-
System policies: These are predefined policies created and maintained by Alibaba Cloud. You can use these policies but cannot modify them. For more information, see Cloud services that support RAM.
NoteThe system automatically flags high-risk system policies (for example, AdministratorAccess and AliyunRAMFullAccess). Avoid granting unnecessary high-risk system policies.
-
Custom policies: These are policies that you create and manage. You can create, update, and delete them. For more information, see Create a custom policy.
-
-
Click OK.
-
-
Click close.