Attaches a control policy to a specified target node.
Operation description
After the control policy is attached, the resource folder or member account is immediately subject to the control policy. Make sure that the result of the attach operation is as expected to avoid impacts on your business.
The system attaches the system policy FullAliyunAccess to resource folders and member accounts by default.
A control policy takes effect on the entire node to which it is attached. Specifically, a control policy attached to a parent resource folder also takes effect on its child resource folders and member accounts.
Each node (resource folder or member account) can have a maximum of 10 control policies attached.
Before calling this operation, call EnableControlPolicy to enable the control policy feature. The enable operation is asynchronous. Poll by calling GetControlPolicyEnablementStatus and confirm that EnablementStatus is Enabled before calling this operation.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
resourcemanager:AttachControlPolicy |
update |
*Account
*Folder
*ControlPolicy
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| PolicyId |
string |
Yes |
The ID of the control policy. |
cp-jExXAqIYkwHN**** |
| TargetId |
string |
Yes |
The ID of the target node. Valid values:
|
fd-ZDNPiT**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
95060F1D-6990-4645-8920-A81D1BBFE992 |
Examples
Success response
JSON format
{
"RequestId": "95060F1D-6990-4645-8920-A81D1BBFE992"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 404 | EntityNotExists.Target | The specified target does not exist in the resource directory. | The specified object does not exist in the resource directory. |
| 404 | EntityNotExists.ResourceControlPolicy | The specified resource control policy does not exist. | |
| 409 | EntityAlreadyExists.ResourceControlPolicy | The resource control policy already exists. | |
| 409 | EntityAlreadyExists.ResourceControlPolicyAttachment | The resource control policy attachment already exists. | |
| 409 | LimitExceeded.ResourceControlPolicyAttachment | The resource control policy attachment number exceeds the limit. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.