All Products
Search
Document Center

Resource Management:DetachPolicy

Last Updated:Aug 28, 2026

Detaches a permission policy from an object. After the policy is detached, the object loses the permissions on the current resource group or the resources within the current account.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

ResourceGroupId

string

Yes

The ID of the resource group or the ID of the Alibaba Cloud account to which the resource group belongs.

Specifies the resource group or Alibaba Cloud account for which you want to revoke permissions.

rg-9gLOoK****

PolicyType

string

Yes

The type of the permission policy. Valid values:

  • Custom

  • System

Custom

PolicyName

string

Yes

The name of the permission policy.

The name must be 1 to 128 characters in length and can contain letters, digits, and hyphens (-).

OSS-Administrator

PrincipalType

string

Yes

The type of the object from which you want to detach the permission policy. Valid values:

  • IMSUser: RAM user

  • IMSGroup: RAM user group

  • ServiceRole: RAM role

IMSUser

PrincipalName

string

Yes

The name of the object from which you want to detach the permission policy.

alice@demo.onaliyun.com

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID.

697852FB-50D7-44D9-9774-530C31EAC572

Examples

Success response

JSON format

{
  "RequestId": "697852FB-50D7-44D9-9774-530C31EAC572"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidParameter.PolicyType The specified policy type is invalid. The specified policy type is invalid.
404 EntityNotExist.Policy The policy does not exist. The policy does not exist.
404 EntityNotExists.ResourceGroup The specified resource group does not exist. You must first create a resource group. The specified resource group does not exist. You must first create a resource group.
409 Invalid.ResourceGroup.Status You cannot perform an operation on a resource group that is being created or deleted. You cannot perform an operation on a resource group that is being created or deleted.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.