After you grant permissions to a RAM user group, all RAM users in the group inherit those permissions. Follow the principle of least privilege and grant only the necessary permissions.
Method 1: Grant permissions on the Groups page
-
Log on to the RAM console as a RAM administrator.
-
In the navigation pane, choose .
-
On the Groups page, find the target RAM user group and click Grant Permissions in the Actions column.
You can also select multiple RAM user groups and click Grant Permissions below the list to grant permissions in bulk.
-
In the Grant Permissions panel, configure the permission grant.
-
Select the resource scope.
-
Account: The permissions apply within the current Alibaba Cloud account.
-
Resource Group: The permissions apply within the specified resource group.
NoteFor permissions to apply to a resource group, the cloud service and resource type must support resource groups. For more information, see Cloud services that support resource groups.
-
-
Select the principal.
The principal is the RAM user group you want to grant permissions to. The system automatically selects this group.
-
Select one or more policies.
A policy is a set of permissions. You can select multiple policies.
-
System policies: Predefined policies created and maintained by Alibaba Cloud. You can use but not modify these policies. For more information, see Cloud services that support RAM.
NoteThe system automatically flags high-risk system policies (for example, AdministratorAccess and AliyunRAMFullAccess). Avoid granting unnecessary high-risk system policies.
-
Custom policies: Policies that you create and manage. You can create, update, and delete custom policies. For more information, see Create a custom policy.
-
-
Click OK.
-
-
Click close.
Method 2: Grant permissions on the Grants page
-
Log on to the RAM console as a RAM administrator.
-
In the navigation pane, choose .
-
On the Grants page, click Grant Permission.
-
In the Grant Permission panel, configure the permission grant.
-
Select the resource scope.
-
Account: The permissions apply within the current Alibaba Cloud account.
-
Resource Group: The permissions apply within the specified resource group.
NoteFor permissions to apply to a resource group, the cloud service and resource type must support resource groups. For more information, see Cloud services that support resource groups.
-
-
Select the principal.
The principal is the RAM user group you want to grant permissions to. You can select multiple RAM user groups.
-
Select one or more policies.
A policy is a set of permissions. You can select multiple policies.
-
System policies: Predefined policies created and maintained by Alibaba Cloud. You can use but not modify these policies. For more information, see Cloud services that support RAM.
NoteThe system automatically flags high-risk system policies (for example, AdministratorAccess and AliyunRAMFullAccess). Avoid granting unnecessary high-risk system policies.
-
Custom policies: Policies that you create and manage. You can create, update, and delete custom policies. For more information, see Create a custom policy.
-
-
Click OK.
-
-
Click close.