After you create resource groups, you can designate an administrator for each resource group. Resource group administrators can grant the operation permissions on the resource groups to other users.


You are a cloud account administrator or a RAM user with administrative permissions on resource groups.

Background information

Before you perform this task, make sure that you understand the relationship between resource group authorization and RAM.

  • RAM offers permission management for resource group authorization.
  • Resource group authorization uses all the policies in RAM. The policies include system policies and custom policies.
  • Resource group authorization grants permissions to RAM users, RAM user groups, or RAM roles.
  • The permissions granted by using RAM take effect on all resources under the relevant Alibaba Cloud account. The permissions granted by using resource group authorization only take effect on resources in a specific resource group.


  1. Log on to the Resource Management console.
  2. In the left-side navigation pane, click Resource Group.
  3. On the page that appears, find the resource group for which you want to add RAM authorization and click Manage Permission in the Actions column.
  4. Click Grant Permission.
  5. Set Principal.
  6. Select the policy you want to attach to the principal.
  7. Click OK.
    Note After the authorization is complete, the principal is granted the relevant permissions on the resources in the resource group.