After a Resource Access Management (RAM) user is granted the relevant permissions, the RAM user can access the required Alibaba Cloud resources. This topic describes how to grant permissions to a RAM user.
Limits
For more information about the maximum numbers of system policies and custom policies that can be attached to each RAM user, see Limits.
Method 1: Grant permissions to a RAM user on the Users page
Log on to the RAM console with an Alibaba Cloud account.
In the left-side navigation pane, choose .
On the Users page, find the required RAM user, and click Add Permissions in the Actions column.
In the Add Permissions panel, grant permissions to the RAM user.
Select the authorization scope.
Alibaba Cloud Account: The permissions take effect on the current Alibaba Cloud account.
Specific Resource Group: The permissions take effect in a specific resource group.
NoteIf you select Specific Resource Group for Authorized Scope, make sure that the cloud service supports resource groups. For more information, see Services that work with Resource Group.
Specify the principal.
The principal is the RAM user to which you want to grant permissions.
Select policies.
RAM supports the following types of policies: system policies and custom policies. You can choose policies based on your business requirements.
NoteYou can attach a maximum of five policies to a RAM user at a time. If you want to attach more than five policies to a RAM user, perform the operation multiple times.
Click OK.
Click Complete.
Method 2: Grant permissions to a RAM user on the Grants page
Log on to the RAM console with an Alibaba Cloud account.
In the left-side navigation pane, choose .
On the Permission page, click Grant Permission.
In the Grant Permission panel, grant permissions to the RAM user.
Select the authorization scope.
Alibaba Cloud Account: The permissions take effect on the current Alibaba Cloud account.
Specific Resource Group: The permissions take effect in a specific resource group.
NoteIf you select Specific Resource Group for Authorized Scope, make sure that the cloud service supports resource groups. For more information, see Services that work with Resource Group.
Specify the principal.
The principal is the RAM user to which you want to grant permissions.
Select policies.
RAM supports the following types of policies: system policies and custom policies. You can choose policies based on your business requirements.
NoteYou can attach a maximum of five policies to a RAM user at a time. If you want to attach more than five policies to a RAM user, perform the operation multiple times.
Click OK.
Click Complete.