All Products
Search
Document Center

Resource Management:Add RAM authorization

Last Updated:Aug 01, 2023

After you create resource groups, you can designate an administrator for each resource group. Resource group administrators can grant the operation permissions on the resource groups to other users.

Prerequisites

You are using an Alibaba Cloud account, or you are a RAM user that has administrative permissions on resource groups.

Background information

Before you perform this task, make sure that you understand the relationship between resource group authorization and RAM.

  • RAM offers permission management for resource group authorization.

  • Resource group authorization uses all the policies in RAM. The policies include system policies and custom policies.

  • Resource group authorization grants permissions to RAM users, RAM user groups, or RAM roles.

  • If the authorization scope is an Alibaba Cloud account, the permissions take effect on all resources within the Alibaba Cloud account. If the authorization scope is a specific resource group, the permissions take effect on all resources in the resource group.

Procedure

  1. Log on to the Resource Management console.

  2. In the left-side navigation pane, choose Resource Group > Resource Group.

  3. On the Resource Group page, find the resource group that you want to manage and click Manage Permission in the Actions column.

  4. Click Grant Permission.

  5. In the Grant Permission panel, set Authorized Scope to Specific Resource Group.

  6. Configure Principal.

  7. Select the policy that you want to attach to the principal.

  8. Click OK.

    Note

    After the authorization is complete, the principal is granted the relevant permissions on the resources in the resource group.