To use the Control Policy feature, you must first enable it.
Effects of enabling control policy
After you enable the Control Policy feature for your Resource Directory, the following changes occur:
-
The
FullAliyunAccesssystem policy is automatically attached to all existing folders and members in your Resource Directory. This policy grants full access to all your Alibaba Cloud resources. -
When you create a folder or member, the
FullAliyunAccesssystem policy is automatically attached to it. -
When an invited Alibaba Cloud account joins your Resource Directory, the
FullAliyunAccesssystem policy is automatically attached to the new member. -
When you remove a member, all Control Policies attached to that member are automatically detached.
Procedure
-
Sign in to the Resource Management console.
-
In the left-side navigation pane, choose .
-
Click Enable Control Policy.
-
In the Enable Control Policy dialog box, click OK.
-
Click Refresh to view the enablement status.
Next steps
After you enable Control Policy, you can create a custom control policy to define specific permission boundaries. For example, you can create a policy that denies a specific action on a resource. You can then attach the policy to a folder or member in your Resource Directory.
When you need to manage permissions for multiple products (such as OSS and VOD), choose the policy creation approach based on clarity and ease of maintenance. If multi-product permissions are closely related and always granted together, you can create a single combined policy. If permissions for different products may be assigned independently or updated at different frequencies, create separate policies for each product to achieve clear responsibility separation, reduce misconfiguration risks, and support flexible permission combinations.
FAQ
Q: After I configure a Simple Log Service (SLS) control policy to restrict regions, why is the Project list not displayed in the console?
Cause: The SLS homepage Project list depends on specific read-only permissions. If you only restrict regions without allowing the necessary list query actions, the console cannot load data for the Project list.
Solution: In the control policy, add an Allow statement for the RAM user. The Allow statement must include the following actions:
-
log:ListProject -
log:GetAcceleration -
log:ListDomains -
log:GetLogging -
log:ListTagResources
Set the Resource element to acs:log:*:*:project/*. This ensures that the Project list is displayed correctly even when region restrictions are applied.
Q: Can control policies (SCP) restrict API operations for specific cloud services, such as Cloud Firewall or Security Center?
A: Support varies by cloud service:
-
Cloud Firewall: Core API operations, such as
DisableInstance, are not explicitly confirmed to support SCP. We recommend that you use RAM permission policies to control these operations within member accounts. -
Security Center: This service is not fully integrated with the SCP control system. Some API operations may not support Deny statements configured through SCP.
-
Before you configure a control policy for a specific cloud service, confirm whether the API operations of that service are integrated with the SCP system.
Q: Do the acs:MFAPresent and acs:RequestTag condition keys take effect for all cloud services?
A: The scope in which these condition keys take effect is limited:
-
acs:MFAPresent: This condition key takes effect only for API operations that support MFA verification. Not all Delete operations support it. For example, theDeleteInstanceoperation of ECS supports this condition key, but you must check the API reference of other services to confirm support. -
acs:RequestTag: This condition key takes effect only for services that support tags and explicitly declare support for this condition key, such as ECS, ApsaraDB RDS, and Server Load Balancer (SLB). Not all services support enforcing tags on requests. -
Before you use a condition key in a control policy, confirm that the target cloud service and API operation support the condition key. Otherwise, the policy may not take effect as expected.
Q: How do I configure a policy to automatically clean up idle accounts under an OU in a resource directory?
A: Alibaba Cloud Resource Management does not provide a feature for automatically cleaning up idle accounts. As an alternative, you can use CloudMonitor (CMS) to monitor account activity, and use Operation Orchestration Service (OOS) or Function Compute to periodically detect idle accounts and send notifications. An administrator can then manually close the accounts that are confirmed to be idle.