This topic lists the services that work with Resource Access Management (RAM), the authorization granularity and system policies for each service, and the links of related topics.

Overview

Each table in this topic contains the following columns:

  • Alibaba Cloud service: the name of the cloud service that supports RAM.
  • Sub-service or sub-module: the sub-service or sub-module of the cloud service. A hyphen (-) indicates none.
  • RAM code: the code that is used in RAM to indicate the cloud service.
  • Console: indicates whether RAM can be used to implement access control in the console of the service. A tick (√) indicates that RAM is supported. A cross (×) indicates that RAM is not supported. A circle (○) indicates that no console is provided for that service.
  • API: indicates whether RAM can be used to implement access control by calling the API of the service. A tick (√) indicates that RAM is supported by calling the API of the service. A cross (×) indicates that RAM is not supported by calling the API of the service. A circle (○) indicates that no API is provided for that service.
  • Authorization granularity: the minimum authorization granularity of the service. A hyphen (-) indicates that no authorization granularity is defined.

    The following authorization granularity is defined:

    • Service: You can control whether RAM users can access the service. You can grant RAM users or RAM roles the permissions to access all or none of the resources in the service.
    • Operation: You can control whether RAM users or RAM roles can perform specific operations on a specific type of resource in the service.
    • Resource: You can control whether RAM users can perform a specific operation on a specific resource in the service. For example, you can authorize a RAM user to restart a specific Elastic Compute Service (ECS) instance.
  • System policy: the system policies that RAM provides for the service. A hyphen (-) indicates that no system policies are provided for the service.
  • References: the topics that are related to both RAM and the service. A hyphen (-) indicates that no topics are related to RAM or the service.

Elastic computing

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
ECSECSecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
Authentication rules
Elastic Block Storage (EBS)EBSecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
-
EBSEBSebsResource
  • AliyunEBSFullAccess
  • AliyunEBSReadOnlyAccess
-
ECSElastic GPU ServiceecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
Authentication rules
ECSECS Bare Metal InstanceecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
Authentication rules
ECSSuper Computing ClusterecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
Authentication rules
ECSDedicated Host (DDH)ecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
Authentication rules
ECSAlibaba Cloud Linux 2ecsResource
  • AliyunECSFullAccess
  • AliyunECSReadOnlyAccess
  • AliyunECSAssistantFullAccess
  • AliyunECSAssistantReadonlyAccess
  • AliyunECSNetworkInterfaceManagementAccess
Authentication rules
Auto Scaling-essOperation
  • AliyunESSFullAccess
  • AliyunESSReadOnlyAccess
API usage instructions
Container Service for Kubernetes (ACK)-csResource
  • AliyunCSFullAccess
  • AliyunCSReadOnlyAccess
Use sub-accounts
Batch Compute-batchcomputeService

-

-
Resource Orchestration Service (ROS)-rosResource
  • AliyunROSFullAccess
  • AliyunROSReadOnlyAccess
Use RAM to control resource access
Function Compute-fcResource
  • AliyunFCFullAccess
  • AliyunFCReadOnlyAccess
  • AliyunFCInvocationAccess
Grant permissions across Alibaba Cloud accounts by using a RAM role
Simple Application Server-swasServiceAliyunSWASFullAccess-
Elastic High Performance Computing (E-HPC)-ehpcService
  • AliyunEHPCFullAccess
  • AliyunEHPCReadOnlyAccess
-
Container Registry-crResource
  • AliyunContainerRegistryFullAccess
  • AliyunContainerRegistryReadOnlyAccess
Configure policies for RAM users to access Container Registry
Elastic Desktop Service (EDS)Wuying Cloud DesktopecdOperation
  • AliyunECDFullAccess
  • AliyunECDReadOnlyAccess
  • AliyunECDRamUserAccess
Grant permissions to RAM users
Elastic Container Instance-eciResource
  • AliyunECIFullAccess
  • AliyunECIReadOnlyAccess
Grant permissions to a RAM user
Serverless Workflow (SWF)-fnfResource
  • AliyunFnFFullAccess
  • AliyunFnFReadOnlyAccess
Authorization policy
Web App Service-webplusOperation
  • AliyunWebPlusFullAccess
  • AliyunWebPlusReadOnlyAccess
-
Compute Nest-
  • computenest
  • computenestsupplier
Resource
  • AliyunComputeNestSupplierFullAccess
  • AliyunComputeNestUserFullAccess
  • AliyunComputeNestUserReadOnlyAccess
  • AliyunComputeNestSupplierReadOnlyAccess
-
Alibaba Cloud Distributed Cloud Container Platform (ACK One)-adcpOperation
  • AliyunAdcpFullAccess
  • AliyunAdcpReadOnlyAccess
-

Database

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
ApsaraDB RDSApsaraDB RDSrdsResource
  • AliyunRDSFullAccess
  • AliyunRDSReadOnlyAccess
  • AliyunRDSGADFullAccess
  • AliyunRDSGADReadOnlyAccess
Use RAM for resource authorization
ApsaraDB RDSApsaraDB RDS for MySQLrdsResource
  • AliyunRDSFullAccess
  • AliyunRDSReadOnlyAccess
Use RAM for resource authorization
ApsaraDB RDSApsaraDB RDS for SQL ServerrdsResource
  • AliyunRDSFullAccess
  • AliyunRDSReadOnlyAccess
Use RAM for resource authorization
ApsaraDB RDSApsaraDB RDS for PostgreSQLrdsResource
  • AliyunRDSFullAccess
  • AliyunRDSReadOnlyAccess
Use RAM for resource authorization
ApsaraDB RDSApsaraDB MyBaserdsResource
  • AliyunRDSFullAccess
  • AliyunRDSReadOnlyAccess
-
ApsaraDB for Redis-kvstoreResource
  • AliyunKvstoreFullAccess
  • AliyunKvstoreReadOnlyAccess
RAM authentication
ApsaraDB for MongoDB-ddsResource
  • AliyunMongoDBFullAccess
  • AliyunMongoDBReadOnlyAccess

-

AnalyticDB for PostgreSQL-gpdbResource
  • AliyunGPDBFullAccess
  • AliyunGPDBReadOnlyAccess
Authentication rules for APIs
Data Transmission Service (DTS)-dtsOperation
  • AliyunDTSFullAccess
  • AliyunDTSReadOnlyAccess
Authorize a RAM user to use DTS
Data Management (DMS)-dmsService
  • AliyunDMSFullAccess
  • AliyunDMSReadOnlyAccess
Authorize DMS to access Alibaba Cloud resources
AnalyticDB for MySQL-adbOperation
  • AliyunADBFullAccess
  • AliyunADBReadOnlyAccess
RAM users and permissions
PolarDB-X-
  • drds
  • polardbx
Resource
  • AliyunDRDSReadOnlyAccess
  • AliyunDRDSFullAccess
Use RAM for resource authorization
ApsaraDB for HBase-hbaseResource
  • AliyunHBaseFullAccess
  • AliyunHBaseReadOnlyAccess
Use RAM for resource authorization
Advanced Database & Application Migration (ADAM)-adamService
  • AliyunADAMReadOnlyAccess
  • AliyunADAMFullAccess
Authorize a RAM user to log on to the ADAM console
PolarDB-polardbOperation
  • AliyunPolardbReadOnlyAccess
  • AliyunPolardbFullAccess
Create and authorize a RAM user
Database Backup (DBS)-dbsService
  • AliyunDBSFullAccess
  • AliyunDBSReadOnlyAccess
-
Database Autonomy Service (DAS)-hdmService
  • AliyunHDMReadOnlyAccess
  • AliyunHDMFullAccess
What do I do if I fail to access DAS as a RAM user due to lack of permissions?
Data Lake Analytics (DLA)-openanalyticsResource
  • AliyunDLAFullAccess
  • AliyunDLAReadOnlyAccess
  • AliyunDLADeveloperAccess
Grant RAM users fine-grained permissions to access DLA
ApsaraDB for OceanBase-oceanbaseService
  • AliyunOceanBaseFullAccess
  • AliyunOceanBaseReadOnlyAccess
-
ApsaraDB for Cassandra-cassandraResource
  • AliyunCassandraFullAccess
  • AliyunCassandraReadOnlyAccess
Manage RAM users
LedgerDB-ledgerdbResource
  • AliyunLedgerDBFullAccess
  • AliyunLedgerDBReadOnlyAccess
RAM user authorization
ApsaraDB for ClickHouse-clickhouseResource
  • AliyunClickHouseFullAccess
  • AliyunClickHouseReadOnlyAccess
RAM-based authorization
Database Gateway (DG)-dgResource
  • AliyunDGFullAccess
  • AliyunDGReadOnlyAccess
-

Storage

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Object Storage Service (OSS)-ossResource
  • AliyunOSSFullAccess
  • AliyunOSSReadOnlyAccess
Overview
Apsara File Storage NAS (NAS)-nasResource
  • AliyunNASFullAccess
  • AliyunNASReadOnlyAccess
Perform access control based on RAM policies
Tablestore-otsResource
  • AliyunOTSFullAccess
  • AliyunOTSReadOnlyAccess
  • AliyunOTSWriteOnlyAccess
Custom permissions
Cloud Storage Gateway (CSG)-hcs-sgwServiceAliyunHCSSGWFullAccessUse RAM to implement account-based access control
Hybrid Backup Recovery (HBR)-hbrResource
  • AliyunHBRFullAccess
  • AliyunHBRReadOnlyAccess
Create a RAM user and authorize the RAM user to access HBR

Cloud communications

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Short Message Service (SMS)-dysmsService

-

-

Networking

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Virtual private cloud (VPC)-vpcResource
  • AliyunVPCFullAccess
  • AliyunVPCReadOnlyAccess
RAM user authorization
Server Load Balancer (SLB)SLBslbResource
  • AliyunSLBReadOnlyAccess
  • AliyunSLBFullAccess
Authorize a RAM user
SLBApplication Load Balancer (ALB)albResource
  • AliyunALBFullAccess
  • AliyunALBReadOnlyAccess
-
SLBNetwork Load Balancer (NLB)nlbResource
  • AliyunNLBFullAccess
  • AliyunNLBReadOnlyAccess
-
Express Connect-vpcResource
  • AliyunExpressConnectFullAccess
  • AliyunExpressConnectReadOnlyAccess
System policies and sample custom policies for Express Connect
Elastic IP Address (EIP)EIPvpcResource
  • AliyunEIPFullAccess
  • AliyunEIPReadOnlyAccess
RAM user authorization
EIPAnycast Elastic IP Address (Anycast EIP)eipanycastResource
  • AliyunAnycastEIPFullAccess
  • AliyunAnycastEIPReadOnlyAccess
RAM authorization
NAT Gateway-vpcResource
  • AliyunNATGatewayReadOnlyAccess
  • AliyunNATGatewayFullAccess
RAM user authorization
VPN Gateway-vpcResource
  • AliyunVPNGatewayFullAccess
  • AliyunVPNGatewayReadOnlyAccess
RAM user authorization
EIP Bandwidth Plan-vpcResource
  • AliyunCommonBandwidthPackageReadOnlyAccess
  • AliyunCommonBandwidthPackageFullAccess
-
Global Accelerator-gaResource
  • AliyunGlobalAccelerationReadOnlyAccess
  • AliyunGlobalAccelerationFullAccess
RAM user authorization
Smart Access Gateway (SAG)-smartagResource

-

RAM authentication
Cloud Enterprise Network (CEN)-cenResource
  • AliyunCENReadOnlyAccess
  • AliyunCENFullAccess
RAM authentication
PrivateLink-privatelinkResource
  • AliyunPrivateLinkFullAccess
  • AliyunPrivateLinkReadOnlyAccess
RAM user authorization
Alibaba Cloud DNS PrivateZone-pvtzResource
  • AliyunPvtzFullAccess
  • AliyunPvtzReadOnlyAccess
RAM
Cloud Data Transfer (CDT)-cdtOperation
  • AliyunCDTFullAccess
  • AliyunCDTReadOnlyAccess
RAM permission policy
VPC peering connection-vpcResource
  • AliyunVpcPeerFullAccess
  • AliyunVpcPeerReadOnlyAccess
-
IPv6 Gateway-vpcResource
  • AliyunIpv6FullAccess
  • AliyunIpv6ReadOnlyAccess
-

O&M management

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Application Real-Time Monitoring Service (ARMS)-armsService
  • AliyunARMSFullAccess
  • AliyunARMSReadOnlyAccess
Grant different permissions to RAM users
CloudMonitor-cmsOperation
  • AliyunCloudMonitorFullAccess
  • AliyunCloudMonitorReadOnlyAccess
  • AliyunCloudMonitorMetricDataReadOnlyAccess
Control permissions of RAM users
Intelligent Advisor-

advisor-intl

Operation
  • AliyunAdvisorFullAccess
  • AliyunAdvisorReadOnlyAccess
-
Cloud Shell-cloudshellOperation--
Cloud Config-configOperation
  • AliyunConfigFullAccess
  • AliyunConfigReadOnlyAccess
RAM user authorization
Logic Composer-composerResource
  • AliyunLogicComposerFullAccess
  • AliyunLogicComposerReadOnlyAccess
Grant permissions to a RAM user
Operation Orchestration Service (OOS)-oosResource
  • AliyunOOSFullAccess
  • AliyunOOSReadOnlyAccess
RAM authorization policies
Cloud Governance CenterCloud Governance CentergovernanceOperation
  • AliyunGovernanceFullAccess
  • AliyunGovernanceReadOnlyAccess
-

Middleware

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Enterprise Distributed Application Service (EDAS)-edasResource
  • AliyunEDASFullAccess
  • AliyunEDASReadOnlyAccess
  • AliyunEDASApplicationFullAccess
  • AliyunEDASApplicationReadOnlyAccess
  • AliyunEDASResourceReadOnlyAccess
  • AliyunEDASResourceFullAccess
Manage RAM users
Message QueueMessage Queue for Apache RocketMQmqResource
  • AliyunMQFullAccess
  • AliyunMQReadOnlyAccess
  • AliyunMQPubOnlyAccess
  • AliyunMQSubOnlyAccess
Grant permissions to RAM users
Message QueueMessage Queue for MQTTmqResource
  • AliyunMQFullAccess
  • AliyunMQReadOnlyAccess
  • AliyunMQPubOnlyAccess
  • AliyunMQSubOnlyAccess
Grant permissions to RAM users
Message QueueMessage Queue for RabbitMQamqpResource
  • AliyunAMQPFullAccess
  • AliyunAMQPReadOnlyAccess
Grant permissions to RAM users
Message Service-mnsResource
  • AliyunMNSFullAccess
  • AliyunMNSReadOnlyAccess
Create a custom policy
Application Configuration Management-acmsResourceAliyunACMFullAccessAccess control
Message Queue for Apache Kafka-alikafkaService
  • AliyunKafkaFullAccess
  • AliyunKafkaReadOnlyAccess
Grant permissions to RAM users
Application High Availability Service-ahasService
  • AliyunAHASFullAccess
  • AliyunAHASReadOnlyAccess

-

Alibaba Cloud Service Mesh (ASM)-servicemeshResource-Overview
EventBridge-eventbridgeResource
  • AliyunEventBridgeFullAccess
  • AliyunEventBridgeReadOnlyAccess
  • AliyunEventBridgeResourceCreatePolicy
  • AliyunEventBridgeResourceDeletePolicy
  • AliyunEventBridgeResourceUpdatePolicy
  • AliyunEventBridgePutEventsPolicy
Policies

Media services and CDN

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
CDN-cdnResource
  • AliyunCDNFullAccess
  • AliyunCDNReadOnlyAccess
RAM authentication
ApsaraVideo Media Processing (MPS)-mtsService
  • AliyunMTSFullAccess
  • AliyunMTSPlayerAuth

-

ApsaraVideo VOD (VOD)-vodOperation
  • AliyunVODFullAccess
  • AliyunVODReadOnlyAccess
  • AliyunVODPlayAuth
  • AliyunVODUploadAuth
-
ApsaraVideo Live-liveResource
  • AliyunLiveFullAccess
  • AliyunLiveReadOnlyAccess
Sub-account console operating instructions
Real-Time Communication-rtcResource

-

-

Dynamic Route for CDN (DCDN)-dcdnResource
  • AliyunDCDNFullAccess
  • AliyunDCDNReadOnlyAccess
-

Enterprise applications

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Direct Mail-dmOperation
  • AliyunDirectMailFullAccess
  • AliyunDirectMailReadOnlyAccess
-
API Gateway-apigatewayService
  • AliyunApiGatewayFullAccess
  • AliyunApiGatewayReadOnlyAccess
Use RAM to manage user permissions for API Gateway
Alibaba Mail-alimailOperation
  • AliyunAlimailFullAccess
  • AliyunAlimailReadOnlyAccess
-
Resource ManagementResource ManagementresourcemanagerOperation
  • AliyunResourceDirectoryFullAccess
  • AliyunResourceDirectoryReadOnlyAccess
RAM authorization
Resource ManagementResource SharingresourcesharingOperation
  • AliyunResourceSharingFullAccess
  • AliyunResourceSharingReadOnlyAccess
-
Resource Managementthe Tag servicetagOperation
  • AliyunTagManagerAccess
  • AliyunTAGReadOnlyAccess
  • AliyunTagAdministratorAccess
Tag
Resource ManagementResource CenterresourcecenterOperation
  • AliyunResourceCenterFullAccess
  • AliyunResourceCenterReadOnlyAccess
Permissions for a RAM user to access Resource Center
BaaSBaaSbaasResource
  • AliyunBaaSFullAccess
  • AliyunBaaSReadOnlyAccess
Hyperledger Fabric RAM authentication
CloudQuotation (CQ)-assettechService
  • AliyunCQLoudFullAccess
  • AliyunCQLoudReadOnlyAccess
-
BizWorks-bizworksService
  • AliyunBizWorksFullAccess
  • AliyunBizWorksReadOnlyAccess
-

Domains and websites

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Alibaba Cloud DNS (DNS)DNSalidnsResource
  • AliyunDNSFullAccess
  • AliyunDNSReadOnlyAccess
RAM authorization
DNSAlibaba Cloud Public DNSpubdnsResource
  • AliyunPubDNSReadOnlyAccess
  • AliyunPubDNSFullAccess
-
Domains-domainResourceAliyunDomainFullAccessAuthentication rules for the Domains API

Artificial intelligence

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Intelligent Speech InteractionIntelligent Speech InteractionnlsService
  • AliyunNLSFullAccess
  • AliyunNLSReadOnlyAccess
-
Machine Learning-paiService--
Machine Learning-paipluginOperation
  • AliyunPaiPluginFullAccess
  • AliyunPaiPluginReadOnlyAccess
-
Image search-imagesearchResource
  • AliyunImagesearchReadOnlyAccess
  • AliyunImagesearchFullAccess
Grant permissions to RAM users
Machine Translation-alimtOperation
  • AliyunMTFullAccess
  • AliyunMTReadOnlyAccess
-

IoT

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
IoT Platform-iotResource
  • AliyunIOTFullAccess
  • AliyunIOTReadOnlyAccess
RAM user access
Link IoT Edge-iotResource
  • AliyunIOTFullAccess
  • AliyunIOTReadOnlyAccess
Access resources of other Alibaba Cloud services
LindormTime Series Database (TSDB)hitsdbOperation

-

-

Big data

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
DataWorks-dataworksOperationAliyunDataWorksFullAccessManage permissions on the DataWorks services and the entities in the DataWorks console by using RAM policies
Quick BI--Service--
DataV-datavServiceAliyunDataVFullAccess-
Realtime Compute for Apache Flink-streamResource
  • AliyunStreamFullAccess
  • AliyunStreamReadOnlyAccess
Grant permissions to a RAM user
Elasticsearch-elasticsearchResource
  • AliyunElasticsearchReadOnlyAccess
  • AliyunElasticsearchFullAccess
Types of resources that can be authorized
E-MapReduceE-MapReduceemrService
  • AliyunEMRFullAccess
  • AliyunEMRFlowAdmin
  • AliyunEMRDevelopAccess
-
Log Service-logResource
  • AliyunLogFullAccess
  • AliyunLogReadOnlyAccess
RAM authentication rules
Hologres-hologramResource
  • AliyunHologresFullAccess
  • AliyunHologresReadOnlyAccess
Grant permissions to a RAM user

Developer services

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Apsara Devops-rdcResource
  • AliyunRDCFullAccess
  • AliyunRDCReadOnlyAccess
-
Tracing Analysis-xtraceOperation
  • AliyunTracingAnalysisFullAccess
  • AliyunTracingAnalysisReadOnlyAccess
-

Security

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Security Center-
  • yundun-sas
  • yundun-aegis
Operation
  • AliyunYundunSASFullAccess
  • AliyunYundunSASReadOnlyAccess
-
Server Guard-yundun-aegisService
  • AliyunYundunAegisFullAccess
  • AliyunYundunAegisReadOnlyAccess
-
Anti-DDoSAnti-DDoSyundun-ddosService
  • AliyunYundunDDosFullAccess
  • AliyunYundunDDosReadOnlyAccess
-
Anti-DDoSAnti-DDoS Pro
  • yundun-high
  • yundun-ddoscoo
Service
  • AliyunYundunHighFullAccess
  • AliyunYundunHighReadOnlyAccess
-
Anti-DDoSAnti-DDoS Premium
  • yundun-high
  • yundun-ddoscoo
Service
  • AliyunYundunAntiDDoSPremiumFullAccess
  • AliyunYundunAntiDDoSPremiumReadOnlyAccess
-
GameShield-yundun-gameshieldService

AliyunYundunGameShieldReadOnlyAccess

-
Web Application Firewall (WAF)WAFyundun-wafOperation
  • AliyunYundunWAFFullAccess
  • AliyunYundunWAFReadOnlyAccess
-
Certificate Management Service-yundun-certService
  • AliyunYundunCertFullAccess
  • AliyunYundunCertReadOnlyAccess
-
Cloud Firewall-yundun-cloudfirewallService
  • AliyunYundunCloudFirewallReadOnlyAccess
  • AliyunYundunCloudFirewallFullAccess
-
Managed Security Service (MSSP)-msspService--
Content Moderation-yundun-greenwebServiceAliyunYundunGreenWebFullAccess-
Bastionhost Bastionhostyundun-bastionhostService
  • AliyunYundunBastionHostFullAccess
  • AliyunYundunBastionHostReadOnlyAccess
  • AliyunYundunBastionHostOperateOnlyAccess
  • AliyunYundunBastionHostAuditOnlyAccess
-
Data Security Center (DSC)-yundun-sddpService
  • AliyunYundunSDDPFullAccess
  • AliyunYundunSDDPReadOnlyAccess
-
Identity as a Service (IDaaS)IDaaSyundun-idaasOperation
  • AliyunYundunIdaasFullAccess
  • AliyunYundunIdaasReadOnlyAccess
-
Key Management Service (KMS)-kmsResource
  • AliyunKMSFullAccess
  • AliyunKMSReadOnlyAccess
  • AliyunKMSCryptoAccess
Use RAM to control access to KMS resources
RAMRAM
  • ram
  • sts
  • ims
Resource
  • AliyunRAMFullAccess
  • AliyunRAMReadOnlyAccess
RAM authentication
RAMCloudSSOcloudssoResource
  • AliyunCloudSSOReadOnlyAccess
  • AliyunCloudSSOFullAccess
-
ActionTrail-actiontrailOperation

-

RAM account authentication

Technical support

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Ticket Management-supportServiceAliyunSupportFullAccess-

Alibaba Cloud Marketplace

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Alibaba Cloud Marketplace-acm×ServiceAliyunMarketplaceFullAccess-

Others

Alibaba Cloud serviceSub-service or sub-moduleRAM codeConsoleAPIAuthorization granularitySystem policyReferences
Billing Management-
  • bss
  • bssapi
  • efc
Operation
  • AliyunBSSFullAccess
  • AliyunBSSReadOnlyAccess
  • AliyunBSSOrderAccess
  • AliyunBSSRefundAccess
  • AliyunBSSRenewReadOnlyAccess
  • AliyunBSSRenewFullAccess

-

ICP Filing-
  • beian
  • bsn
ServiceAliyunBeianFullAccess-