All Products
Search
Document Center

Resource Management:Use CloudSSO to centrally manage the identities and permissions of multiple accounts

Last Updated:Jun 02, 2026

Use CloudSSO and Resource Directory to set up centralized identity management and access control across multiple Alibaba Cloud accounts.

Objective

CloudSSO integrates with Resource Directory to provide centralized multi-account identity management and access control. A CloudSSO administrator can create users, define access configurations that bundle permissions, and provision those configurations to members in a resource directory—all from a single place. CloudSSO users then log on to the CloudSSO user portal, where they can see every member they have access to and switch into each one with the assigned permissions.

This tutorial walks through a complete setup using the following named entities:

  • User: user1 (a new CloudSSO user)

  • Access configuration: a configuration that grants the AliyunVPCFullAccess system policy

  • Target member: Sandbox Account (a member in the resource directory)

After completing this tutorial, user1 can log on to the CloudSSO user portal and access only virtual private cloud (VPC) resources within Sandbox Account.

Prerequisites

Before you begin, make sure you have:

Set up centralized access

  1. Log on to the CloudSSO console.

  2. Create a CloudSSO user.

    In this example, create a user named user1.

    For more information, see Create a user.

  3. Enable username-password logon for the CloudSSO user.

    For more information, see Enable username-password logon.

  4. Create an access configuration.

    An access configuration defines the permissions that CloudSSO users get when they access a member account. Without an access configuration, users can log on to the portal but cannot access any resources. In this example, the access configuration includes only the AliyunVPCFullAccess system policy, with no inline policies.

    For more information, see Overview and Create a permission set.

  5. Grant user1 access to Sandbox Account.

    Authorize user1 to access VPC resources within Sandbox Account by provisioning the access configuration to that member.

    For more information, see Assign access to a member account.

  6. Verify access as user1.

    1. Log on to the CloudSSO user portal using user1's username and password.

    2. Select Sandbox Account from the member list.

    3. Access VPC resources within Sandbox Account using the assigned RAM role.

    For more information, see Sign in to the CloudSSO user portal.

What's next

Repeat the steps above to create additional CloudSSO users, define more access configurations with different permission scopes, and provision them to other members in the resource directory. This lets you manage identities and permissions across all Alibaba Cloud accounts from a single point.

To further streamline access management, synchronize users from an external identity provider (IdP) and let them access member accounts through single sign-on (SSO). For more information, see What is CloudSSO?