If a Resource Access Management (RAM) role no longer needs specific permissions, you can remove the permissions from the RAM role. This topic describes how to remove the permissions from a RAM role.
Note You cannot remove permissions from service-linked roles by detaching policies from
the roles. This is because the policies that are attached to this type of role are
defined by the linked cloud services. For more information, see Service-linked roles.
Method 1: Remove permissions from a RAM role on the RAM Roles page
- Log on to the RAM console by using your Alibaba Cloud account.
- In the left-side navigation pane, choose .
- On the Roles page, find the required RAM role.
- On the page that appears, click the Permissions tab, find the policies that you want to detach from the RAM role, and then click Remove Permission in the Actions column.
- In the Revoke Permission message, click Revoke Permission.
Method 2: Remove permissions from a RAM role on the Grants page
- Log on to the RAM console by using your Alibaba Cloud account.
- In the left-side navigation pane, choose .
- On the Grants page, find the RAM role from which you want to remove permissions and click Revoke Permission in the Actions column.
- In the Revoke Permission message, click Revoke Permission.