All Products
Search
Document Center

Resource Management:ListPolicyAttachments

Last Updated:Aug 31, 2026

Queries the list of policy attachments by calling ListPolicyAttachments.

Operation description

You can query the following information:

  • All authorization records under an Alibaba Cloud account or a resource group.

  • All access policies granted to a Resource Access Management (RAM) user, RAM user group, or RAM role.

  • RAM users, RAM user groups, and RAM roles that have a specific permission under an Alibaba Cloud account or a resource group.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

ResourceGroupId

string

No

The ID of the resource group or the Alibaba Cloud account ID to which the resource group belongs. If this parameter is left empty, all authorization records under the current account are listed.

rg-001

PolicyType

string

No

The type of the access policy. If this parameter is left empty, all types of access policies are listed.

  • Custom: custom policy.

  • System: system policy.

System

PolicyName

string

No

Policy Name of the access policy.

Policy Name must be 1 to 128 characters in length and can contain letters, digits, and hyphens (-).

AdministratorAccess

PrincipalType

string

No

The authorization object type. If this parameter is left empty, all types of authorization objects are listed.

  • IMSUser: Resource Access Management (RAM) user.

  • IMSGroup: RAM user group.

  • ServiceRole: RAM role.

IMSUser

PrincipalName

string

No

The name of the principal.

alice@demo.onaliyun.com

PageNumber

integer

No

The page number.

Minimum value: 1. Default value: 1.

1

PageSize

integer

No

The number of entries per page.

Valid values: 1 to 100. Default value: 10.

10

Language

string

No

The language type. The description of the system access policy is returned in the specified language.

  • en: English.

  • zh-CN: Chinese.

  • ja: Japanese.

zh-CN

Response elements

Element

Type

Description

Example

object

PageNumber

integer

The page number.

1

PageSize

integer

The number of entries per page.

10

PolicyAttachments

object

PolicyAttachment

array<object>

The access policy information.

object

The access policy information.

AttachDate

string

The time when the policy was attached. The time is in RFC 3339 UTC format, indicated by Z.

2015-01-23T12:33:18Z

Description

string

The description of the access policy.

Administrator permissions

PolicyName

string

The name of the access policy.

AdministratorAccess

PolicyType

string

The type of the access policy.

  • Custom: custom policy.

  • System: system policy.

System

PrincipalName

string

The name of the principal.

alice@demo.onaliyun.com

PrincipalType

string

The authorization object type.

  • IMSUser: Resource Access Management (RAM) user.

  • IMSGroup: RAM user group.

  • ServiceRole: RAM role.

IMSUser

ResourceGroupId

string

The ID of the resource group or the Alibaba Cloud account ID to which the resource group belongs.

rg-9gLOoK****

RequestId

string

The request ID.

7B8A4E7D-6CFF-471D-84DF-195A7A241ECB

TotalCount

integer

The total number of entries returned.

2

Examples

Success response

JSON format

{
  "PageNumber": 1,
  "PageSize": 10,
  "PolicyAttachments": {
    "PolicyAttachment": [
      {
        "AttachDate": "2015-01-23T12:33:18Z",
        "Description": "管理员权限",
        "PolicyName": "AdministratorAccess",
        "PolicyType": "System",
        "PrincipalName": "alice@demo.onaliyun.com",
        "PrincipalType": "IMSUser",
        "ResourceGroupId": "rg-9gLOoK****"
      }
    ]
  },
  "RequestId": "7B8A4E7D-6CFF-471D-84DF-195A7A241ECB",
  "TotalCount": 2
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidParameter.PolicyType The specified policy type is invalid. The specified policy type is invalid.
404 EntityNotExists.ResourceGroup The specified resource group does not exist. You must first create a resource group. The specified resource group does not exist.
404 EntityNotExist.Policy The policy does not exist. The policy does not exist.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.