All Products
Search
Document Center

Identity as a Service:RAM authorization

Last Updated:Feb 05, 2026

Resource Access Management (RAM) is a service provided by Alibaba Cloud to manage user identities and resource access permissions. Using RAM helps you avoid sharing your Alibaba Cloud account keys with other users and allows you to grant users the least privilege access. RAM uses permission policies to define authorizations. This topic describes the general structure of a RAM policy, and the policy statement elements (Action, Resource, and Condition) defined by Identity as a Service for RAM permission policies. The RAM code (RamCode) for Identity as a Service is eiam , and the supported authorization granularity is RESOURCE .

General structure of a policy

Permission policies support JSON format with the following general structure:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

The following list describes the fields in the policy:

  • Version: Specifies the policy version number. It is fixed at 1.

  • Statement:

    • Effect: Specifies the authorization result. Valid values: Allow and Deny.

    • Action: Specifies one or more operations that are allowed or denied.

    • Resource: Specifies the specific objects affected by the operations. You can use Alibaba Cloud Resource Names (ARNs) to describe specific resources.

    • Condition: Specifies the conditions for the authorization to take effect. This field is optional.

      • Condition operator: Specifies the conditional operators. Different types of conditions support different conditional operators.

      • Condition_key: Specifies the condition keys.

      • Condition_value: Specifies the condition values.

Action

The following table lists the actions defined by Identity as a Service. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that support authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding ARN in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys that are applicable across all RAM-integrated services. For more information, see Common condition keys.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

API

Access level

Resource type

Condition key

Dependent action

eiam:EnableFederatedCredentialProvider EnableFederatedCredentialProvider update

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}

None None
eiam:SetPasswordExpirationConfiguration SetPasswordExpirationConfiguration update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:EnableApplicationFederatedCredential EnableApplicationFederatedCredential update

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}

None None
eiam:SetIdentityProviderUdPullConfiguration SetIdentityProviderUdPullConfiguration update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:DisableUser DisableUser update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:DeleteApplicationToken DeleteApplicationToken delete

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/{#ApplicationTokenId}

None None
eiam:GetFederatedCredentialProvider GetFederatedCredentialProvider get

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}

None None
eiam:ListGroups ListGroups list

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/*

None None
eiam:ListOrganizationalUnitsForResourceServer ListOrganizationalUnitsForResourceServer list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetPasswordInitializationConfiguration GetPasswordInitializationConfiguration get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:SetApplicationGrantScope SetApplicationGrantScope update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateOrganizationalUnitParentId UpdateOrganizationalUnitParentId update

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:ListApplicationFederatedCredentialsForProvider ListApplicationFederatedCredentialsForProvider list

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/*/applicationfederatedcredential/*

None None
eiam:GetCustomPrivacyPolicy GetCustomPrivacyPolicy get

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#CustomPrivacyPolicyId}

None None
eiam:EnableConditionalAccessPolicy EnableConditionalAccessPolicy update

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}

None None
eiam:UpdateResourceServerScope UpdateResourceServerScope update

*ResourceServerScope

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/resourceserverscope/{#ResourceServerScopeId}

None None
eiam:EnableApplicationSso EnableApplicationSso update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableApplicationApiInvoke EnableApplicationApiInvoke update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetApplicationTemplate GetApplicationTemplate get

*ApplicationTemplate

acs:eiam:{#regionId}:{#accountId}:applicationtemplate/{#ApplicationTemplateId}

None None
eiam:SetPasswordComplexityConfiguration SetPasswordComplexityConfiguration update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:ObtainApplicationClientSecret ObtainApplicationClientSecret get

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/{#SecretId}

None None
eiam:CreateBrand CreateBrand create

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/*

None None
eiam:CheckInstanceForDelete CheckInstanceForDelete get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:UpdateNetworkZoneDescription UpdateNetworkZoneDescription update

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}

None None
eiam:UpdateInstanceDescription UpdateInstanceDescription update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#instanceId}

None None
eiam:CreateUser CreateUser create

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/*

None None
eiam:DeleteApplication DeleteApplication delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:CreateApplication CreateApplication create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/*

None None
eiam:CreateDomain CreateDomain create

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/*

None None
eiam:RemoveCustomPrivacyPoliciesFromBrand RemoveCustomPrivacyPoliciesFromBrand update

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#PolicyId}

None None
eiam:GetApplicationProvisioningUserPrimaryOrganizationalUnit GetApplicationProvisioningUserPrimaryOrganizationalUnit get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListOrganizationalUnits ListOrganizationalUnits list

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/*

None None
eiam:SetLoginRedirectApplicationForBrand SetLoginRedirectApplicationForBrand update

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:CreateOrganizationalUnit CreateOrganizationalUnit create

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/*

None None
eiam:RevokeResourceServerScopesFromGroup RevokeResourceServerScopesFromGroup delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:DeleteConditionalAccessPolicy DeleteConditionalAccessPolicy delete

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}

None None
eiam:ListSynchronizationJobs ListSynchronizationJobs list

*SynchronizationJob

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/synchronizationjob/*

None None
eiam:EnableApplication EnableApplication update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListApplicationClientSecrets ListApplicationClientSecrets list

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/*

None None
eiam:ListUsersForAuthorizationRule ListUsersForAuthorizationRule list

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

None None
eiam:SetInstanceControlConfiguration SetInstanceControlConfiguration update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:UnlockUser UnlockUser update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:ListCustomPrivacyPolicies ListCustomPrivacyPolicies list

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/*

None None
eiam:UpdateApplicationInfo UpdateApplicationInfo update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListCloudAccounts ListCloudAccounts list

*CloudAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/*

None None
eiam:ListNetworkAccessEndpointAvailableRegions ListNetworkAccessEndpointAvailableRegions get

*All Resource

*

None None
eiam:UpdateDomainIcpNumber UpdateDomainIcpNumber update

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}

None None
eiam:GetPasswordExpirationConfiguration GetPasswordExpirationConfiguration get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:ListApplicationsForAuthorizationRule ListApplicationsForAuthorizationRule list

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/AuthorizationRule/{#AuthorizationRuleId}

None None
eiam:CreateNetworkZone CreateNetworkZone create

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/*

None None
eiam:DeleteApplicationClientSecret DeleteApplicationClientSecret delete

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/{#SecretId}

None None
eiam:DeleteCustomPrivacyPolicy DeleteCustomPrivacyPolicy delete

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#CustomPrivacyPolicyId}

None None
eiam:RemoveApplicationFromAuthorizationRule RemoveApplicationFromAuthorizationRule delete

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetApplicationSsoConfig GetApplicationSsoConfig get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateCloudAccountDescription UpdateCloudAccountDescription update

*CloudAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}

None None
eiam:UpdateOrganizationalUnit UpdateOrganizationalUnit update

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:DeleteCloudAccount DeleteCloudAccount delete

*CloudAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}

None None
eiam:DeleteResourceServerScope DeleteResourceServerScope delete

*ResourceServerScope

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/resourceserverscope/{#ResourceServerScopeId}

None None
eiam:ListNetworkZones ListNetworkZones list

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/*

None None
eiam:RemoveGroupFromAuthorizationRule RemoveGroupFromAuthorizationRule delete

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:EnableApplicationToken EnableApplicationToken update

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/{#ApplicationTokenId}

None None
eiam:GetApplicationGrantScope GetApplicationGrantScope get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListConditionalAccessPoliciesForNetworkZone ListConditionalAccessPoliciesForNetworkZone list

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}

None None
eiam:CreateIdentityProviderStatusCheckJob CreateIdentityProviderStatusCheckJob create

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:ListApplicationAccountsForUser ListApplicationAccountsForUser get

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

*ApplicationAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationaccount/*

None None
eiam:GetSynchronizationJob GetSynchronizationJob get

*SynchronizationJob

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/synchronizationjob/{#SynchronizationJobId}

None None
eiam:ListGroupsForApplication ListGroupsForApplication list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableApplicationM2MClient EnableApplicationM2MClient update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetIdentityProviderUdPushConfiguration GetIdentityProviderUdPushConfiguration get

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:CreateNetworkAccessEndpoint CreateNetworkAccessEndpoint create

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/*

None None
eiam:ListConditionalAccessPoliciesForUser ListConditionalAccessPoliciesForUser list

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*

None None
eiam:DeleteCustomField DeleteCustomField delete

*CustomField

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/{#FieldId}

None None
eiam:ObtainApplicationToken ObtainApplicationToken get

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/{#ApplicationTokenId}

None None
eiam:UpdateGroup UpdateGroup update

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:CreateCloudAccountRole CreateCloudAccountRole create

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}/cloudaccountrole/*

None None
eiam:GetApplicationFederatedCredential GetApplicationFederatedCredential get

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}

None None
eiam:UpdateUserPassword UpdateUserPassword update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:UpdateAuthorizationRuleDescription UpdateAuthorizationRuleDescription update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}

None None
eiam:EnableClientPublicKey EnableClientPublicKey update

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/{#ClientPublicKeyId}

None None
eiam:SetInstanceGlobalizationConfig SetInstanceGlobalizationConfig update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:UpdateNetworkAccessEndpointName UpdateNetworkAccessEndpointName update

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}

None None
eiam:ListActionTrackEventTypes ListActionTrackEventTypes list

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:RevokeApplicationFromGroups RevokeApplicationFromGroups delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DisableApplicationApiInvoke DisableApplicationApiInvoke update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateGroupDescription UpdateGroupDescription update

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:UpdateApplicationDescription UpdateApplicationDescription update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:CreateApplicationFederatedCredential CreateApplicationFederatedCredential create

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/*

None None
eiam:DisableApplicationResourceServer DisableApplicationResourceServer update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableDomainProxyToken EnableDomainProxyToken update

*DomainProxyToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/{#DomainProxyTokenId}

None None
eiam:DisableClientPublicKey DisableClientPublicKey update

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/{#ClientPublicKeyId}

None None
eiam:UpdateApplicationAdvancedConfig UpdateApplicationAdvancedConfig update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableIdentityProviderUdPull EnableIdentityProviderUdPull update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:DeleteNetworkAccessEndpoint DeleteNetworkAccessEndpoint delete

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}

None None
eiam:AddGroupToAuthorizationRule AddGroupToAuthorizationRule create

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:UpdateAuthorizationRuleApplicationAttachment UpdateAuthorizationRuleApplicationAttachment update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateApplicationClientSecretExpirationTime UpdateApplicationClientSecretExpirationTime update

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/{#SecretId}

None None
eiam:DisableCustomPrivacyPolicy DisableCustomPrivacyPolicy update

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#CustomPrivacyPolicyId}

None None
eiam:DisableResourceServerCustomSubject DisableResourceServerCustomSubject update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ObtainDomainProxyToken ObtainDomainProxyToken get

*DomainProxyToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/{#DomainProxyTokenId}

None None
eiam:AuthorizeResourceServerScopesToOrganizationalUnit AuthorizeResourceServerScopesToOrganizationalUnit create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:GetDomainDnsChallenge GetDomainDnsChallenge get

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/*

None None
eiam:DisableIdentityProviderAdvancedAbility DisableIdentityProviderAdvancedAbility update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:GetForgetPasswordConfiguration GetForgetPasswordConfiguration get

*AuthenticationSource

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GetNetworkZone GetNetworkZone get

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}

None None
eiam:GetCustomField GetCustomField get

*CustomField

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/{#FieldId}

None None
eiam:GetCloudAccountRole GetCloudAccountRole get

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/${#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}

None None
eiam:ListUserAuthnSourceMappings ListUserAuthnSourceMappings list

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/*

None None
eiam:ListApplicationFederatedCredentials ListApplicationFederatedCredentials list

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/*

None None
eiam:ListGroupsForResourceServer ListGroupsForResourceServer list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateConditionalAccessPolicyDescription UpdateConditionalAccessPolicyDescription update

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}

None None
eiam:UpdateApplicationRole UpdateApplicationRole update

*ApplicationRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/{#ApplicationRoleId}

None None
eiam:SetUserPrimaryOrganizationalUnit SetUserPrimaryOrganizationalUnit update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:GetPasswordHistoryConfiguration GetPasswordHistoryConfiguration get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:DeleteApplicationRole DeleteApplicationRole delete

*ApplicationRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/{#ApplicationRoleId}

None None
eiam:UpdateNetworkZone UpdateNetworkZone update

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}

None None
eiam:GetNetworkAccessEndpoint GetNetworkAccessEndpoint get

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}

None None
eiam:RenewFreeLicenseEndTime RenewFreeLicenseEndTime update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:ListDomains ListDomains list

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/*

None None
eiam:ListResourceServersForUser ListResourceServersForUser list

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:GetGroup GetGroup get

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:ListAuthorizationRules ListAuthorizationRules list

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/*

None None
eiam:UpdateApplicationRoleDescription UpdateApplicationRoleDescription update

*ApplicationRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/{#ApplicationRoleId}

None None
eiam:RevokeResourceServerScopesFromOrganizationalUnit RevokeResourceServerScopesFromOrganizationalUnit delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:ListUsers ListUsers list

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/*

None None
eiam:GenerateDownloadUrlForSynchronizationJob GenerateDownloadUrlForSynchronizationJob none

*SynchronizationJob

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/synchronizationjob/{#SynchronizationJobId}

None None
eiam:ListGroupsForAuthorizationRule ListGroupsForAuthorizationRule list

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/AuthorizationRule/{#AuthorizationRuleId}

None None
eiam:RunSynchronizationJob RunSynchronizationJob create

*SynchronizationJob

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/synchronizationjob/*

None None
eiam:DisableApplicationToken DisableApplicationToken update

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/{#ApplicationTokenId}

None None
eiam:UnbindUserAuthnSourceMapping UnbindUserAuthnSourceMapping update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:DeleteUsers DeleteUsers delete

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/*

None None
eiam:DeleteNetworkZone DeleteNetworkZone delete

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}

None None
eiam:ListApplicationRoles ListApplicationRoles list

*ApplicationRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/*

None None
eiam:DeleteFederatedCredentialProvider DeleteFederatedCredentialProvider delete

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}

None None
eiam:DeleteDomainProxyToken DeleteDomainProxyToken delete

*DomainProxyToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/{#DomainProxyTokenId}

None None
eiam:ListCustomPrivacyPoliciesForBrand ListCustomPrivacyPoliciesForBrand list

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:CheckApplicationProvisioningUserPrimaryOrganizationalUnit CheckApplicationProvisioningUserPrimaryOrganizationalUnit none

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListAuthorizationRulesForApplication ListAuthorizationRulesForApplication list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableUser EnableUser update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:SetApplicationProvisioningUserPrimaryOrganizationalUnit SetApplicationProvisioningUserPrimaryOrganizationalUnit update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateApplicationFederatedCredentialDescription UpdateApplicationFederatedCredentialDescription update

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}

None None
eiam:ListUsersForGroup ListUsersForGroup get

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:CreateGroup CreateGroup create

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/*

None None
eiam:GetDomain GetDomain get

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}

None None
eiam:ListOrganizationalUnitParents ListOrganizationalUnitParents get

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:GetCloudAccount GetCloudAccount get

*CloudAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}

None None
eiam:DeleteInstance DeleteInstance delete

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:CreateClientPublicKey CreateClientPublicKey none

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/*

None None
eiam:ListAuthorizationRulesForGroup ListAuthorizationRulesForGroup list

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:DisableIdentityProviderUdPull DisableIdentityProviderUdPull update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:DisableApplicationFederatedCredential DisableApplicationFederatedCredential update

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}

None None
eiam:CreateIdentityProvider CreateIdentityProvider create

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/*

None None
eiam:AddApplicationAccountToUser AddApplicationAccountToUser create

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

*ApplicationAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationaccount/*

None None
eiam:ListNetworkAccessEndpointAvailableZones ListNetworkAccessEndpointAvailableZones get

*All Resource

*

None None
eiam:GetOrganizationalUnit GetOrganizationalUnit get

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:ListNetworkAccessEndpoints ListNetworkAccessEndpoints get

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/*

None None
eiam:CreateCloudAccount CreateCloudAccount create

*CloudAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/*

None None
eiam:DeleteAuthorizationRule DeleteAuthorizationRule delete

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}

None None
eiam:EnableCustomField EnableCustomField update

*CustomField

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/{#FieldId}

None None
eiam:EnableAuthorizationRule EnableAuthorizationRule update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}

None None
eiam:DeleteBrand DeleteBrand delete

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:SetDefaultDomain SetDefaultDomain update

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}

None None
eiam:GetIdentityProviderStatusCheckJob GetIdentityProviderStatusCheckJob get

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:ListApplicationAccounts ListApplicationAccounts list

*ApplicationAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationaccount/*

None None
eiam:GetConditionalAccessPolicy GetConditionalAccessPolicy get

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}

None None
eiam:ListBrands ListBrands list

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/*

None None
eiam:CreateAuthorizationRule CreateAuthorizationRule create

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/*

None None
eiam:GetResourceServerScope GetResourceServerScope get

*ResourceServerScope

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/resourceserverscope/{#ResourceServerScopeId}

None None
eiam:GetInstanceQuota GetInstanceQuota get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:ExecIdentityProviderMetadataUrlResolution ExecIdentityProviderMetadataUrlResolution get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:RevokeApplicationFromUsers RevokeApplicationFromUsers delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DisableIdentityProviderAuthn DisableIdentityProviderAuthn update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:SetIdentityProviderAuthnConfiguration SetIdentityProviderAuthnConfiguration update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:ListOrganizationalUnitsForApplication ListOrganizationalUnitsForApplication list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateApplicationSsoFormParams UpdateApplicationSsoFormParams update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:AddUserToOrganizationalUnits AddUserToOrganizationalUnits create

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:RevokeResourceServerScopesFromClient RevokeResourceServerScopesFromClient delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableResourceServerCustomSubject EnableResourceServerCustomSubject update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateAuthorizationRuleUserAttachment UpdateAuthorizationRuleUserAttachment update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:CreateApplicationRole CreateApplicationRole create

*ApplicationRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/*

None None
eiam:SetApplicationResourceServerIdentifier SetApplicationResourceServerIdentifier update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DeleteAuthorizationResource DeleteAuthorizationResource delete

*AuthorizationResource

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}/authorizationresource/{#AuthorizationResourceId}

None None
eiam:DisableInitDomainAutoRedirect DisableInitDomainAutoRedirect update

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/*

None None
eiam:RevokeResourceServerScopesFromUser RevokeResourceServerScopesFromUser delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:DeleteWebAuthnAuthenticator DeleteWebAuthnAuthenticator delete

*Authenticator

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}/authenticator/{#AuthenticatorId}

None None
eiam:EnableInternalAuthenticationSource EnableInternalAuthenticationSource update

*AuthenticationSource

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authenticationsource/{#AuthenticationSourceId}

None None
eiam:EnableCloudAccountRole EnableCloudAccountRole update

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}

None None
eiam:AddUsersToGroup AddUsersToGroup create

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:DeleteIdentityProvider DeleteIdentityProvider delete

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:CheckInstanceModuleStatus CheckInstanceModuleStatus get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:AuthorizeResourceServerToClient AuthorizeResourceServerToClient update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:AuthorizeResourceServerScopesToGroup AuthorizeResourceServerScopesToGroup create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:DisableCustomField DisableCustomField update

*CustomField

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/{#FieldId}

None None
eiam:ListClientPublicKeys ListClientPublicKeys list

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/*

None None
eiam:UpdateAuthorizationRule UpdateAuthorizationRule update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}

None None
eiam:GetAuthorizationResource GetAuthorizationResource get

*AuthorizationResource

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}/authorizationresource/{#AuthorizationResourceId}

None None
eiam:GetUser GetUser get

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:ListApplicationsForUser ListApplicationsForUser list

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:AuthorizeResourceServerScopesToClient AuthorizeResourceServerScopesToClient create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetInstanceLicense GetInstanceLicense get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:DeleteClientPublicKey DeleteClientPublicKey delete

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/{#ClientPublicKeyId}

None None
eiam:SetPrimaryClientPublicKey SetPrimaryClientPublicKey update

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/{#ClientPublicKeyId}

None None
eiam:AuthorizeApplicationToUsers AuthorizeApplicationToUsers update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:AuthorizeResourceServerScopesToUser AuthorizeResourceServerScopesToUser create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:CreateCustomField CreateCustomField create

*CustomField

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/*

None None
eiam:CreateAuthorizationResource CreateAuthorizationResource create

*AuthorizationResource

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}/authorizationresource/*

None None
eiam:CreateConditionalAccessPolicy CreateConditionalAccessPolicy create

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*

None None
eiam:UnbindTotpAuthenticator UnbindTotpAuthenticator update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:RevokeResourceServerFromClient RevokeResourceServerFromClient delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListAuthorizationResources ListAuthorizationResources list

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GetPasswordComplexityConfiguration GetPasswordComplexityConfiguration get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GetApplication GetApplication get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateCloudAccountRoleDescription UpdateCloudAccountRoleDescription update

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}

None None
eiam:DisableAuthorizationRule DisableAuthorizationRule update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}

None None
eiam:RevokeApplicationFromOrganizationalUnits RevokeApplicationFromOrganizationalUnits delete

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:CreateInstanceTrialLicense CreateInstanceTrialLicense create

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:DisableApplicationClientSecret DisableApplicationClientSecret update

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/{#SecretId}

None None
eiam:GetIdentityProviderUdPullConfiguration GetIdentityProviderUdPullConfiguration get

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:UpdateApplicationTokenExpirationTime UpdateApplicationTokenExpirationTime update

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/{#ApplicationTokenId}

None None
eiam:ListIdentityProvidersForNetworkAccessEndpoint ListIdentityProvidersForNetworkAccessEndpoint get

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}

None None
eiam:CreateInstance CreateInstance create

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/*

None None
eiam:GetApplicationProvisioningConfig GetApplicationProvisioningConfig get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:AuthorizeApplicationToOrganizationalUnits AuthorizeApplicationToOrganizationalUnits create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListApplications ListApplications list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/*

None None
eiam:DeleteCloudAccountRole DeleteCloudAccountRole delete

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/${#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}

None None
eiam:CreateFederatedCredentialProvider CreateFederatedCredentialProvider create

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/*

None None
eiam:GetServiceQuota GetServiceQuota get

*All Resource

*

None None
eiam:UpdateApplicationAuthorizationType UpdateApplicationAuthorizationType update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableBrand EnableBrand update

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:RemoveApplicationAccountFromUser RemoveApplicationAccountFromUser delete

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

*ApplicationAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationaccount/{#ApplicationAccountId}

None None
eiam:DisableDomainProxyToken DisableDomainProxyToken update

*DomainProxyToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/{#DomainProxyTokenId}

None None
eiam:UpdateFederatedCredentialProvider UpdateFederatedCredentialProvider update

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}

None None
eiam:GenerateFileImportTemplate GenerateFileImportTemplate update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GetInstanceModuleInfo GetInstanceModuleInfo get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:RemoveUserFromAuthorizationRule RemoveUserFromAuthorizationRule delete

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:EnableApplicationProvisioning EnableApplicationProvisioning update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateConditionalAccessPolicy UpdateConditionalAccessPolicy update

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}

None None
eiam:UpdateCustomPrivacyPolicy UpdateCustomPrivacyPolicy update

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#CustomPrivacyPolicyId}

None None
eiam:ListApplicationsForNetworkZone ListApplicationsForNetworkZone list

*NetworkZone

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/*

None None
eiam:EnableInitDomainAutoRedirect EnableInitDomainAutoRedirect update

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/*

None None
eiam:ListUsersForResourceServer ListUsersForResourceServer list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:UpdateAuthorizationRuleGroupAttachment UpdateAuthorizationRuleGroupAttachment update

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:ListEventTypes ListEventTypes list

*All Resource

*

None None
eiam:ListApplicationsForOrganizationalUnit ListApplicationsForOrganizationalUnit list

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:SetApplicationProvisioningConfig SetApplicationProvisioningConfig update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListApplicationsForNetworkAccessEndpoint ListApplicationsForNetworkAccessEndpoint get

*NetworkAccessEndpoint

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}

None None
eiam:UpdateOrganizationalUnitDescription UpdateOrganizationalUnitDescription update

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:GetClientPublicKey GetClientPublicKey get

*ClientPublicKey

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/{#ClientPublicKeyId}

None None
eiam:AddCustomPrivacyPoliciesToBrand AddCustomPrivacyPoliciesToBrand update

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#PolicyId}

None None
eiam:ListInstances ListInstances get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/*

None None
eiam:RemoveUsersFromGroup RemoveUsersFromGroup delete

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:SetWebAuthnConfiguration SetWebAuthnConfiguration update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:UpdateUserDescription UpdateUserDescription update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:BindUserAuthnSourceMapping BindUserAuthnSourceMapping update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:GetLoginRedirectApplicationForBrand GetLoginRedirectApplicationForBrand get

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:ListApplicationSupportedProvisionProtocolTypes ListApplicationSupportedProvisionProtocolTypes list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DisableApplication DisableApplication update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableCustomPrivacyPolicy EnableCustomPrivacyPolicy update

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#CustomPrivacyPolicyId}

None None
eiam:DeleteOrganizationalUnit DeleteOrganizationalUnit delete

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:ListCloudAccountRoles ListCloudAccountRoles list

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}/cloudaccountrole/*

None None
eiam:EnableApplicationResourceServer EnableApplicationResourceServer update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:SetPasswordInitializationConfiguration SetPasswordInitializationConfiguration update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:AuthorizeApplicationToGroups AuthorizeApplicationToGroups create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListEiamInstances ListEiamInstances list

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/*

None None
eiam:GetIdentityProvider GetIdentityProvider get

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:ListIdentityProviders ListIdentityProviders list

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/*

None None
eiam:DisableFederatedCredentialProvider DisableFederatedCredentialProvider update

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}

None None
eiam:DeleteDomain DeleteDomain delete

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}

None None
eiam:CreateCustomPrivacyPolicy CreateCustomPrivacyPolicy create

*CustomPrivacyPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/*

None None
eiam:DisableBrand DisableBrand update

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:UpdateCloudAccount UpdateCloudAccount update

*CloudAccount

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}

None None
eiam:GetApplicationAdvancedConfig GetApplicationAdvancedConfig get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DeleteOrganizationalUnitChildren DeleteOrganizationalUnitChildren delete

*OrganizationalUnit

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}

None None
eiam:ListApplicationsForGroup ListApplicationsForGroup get

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:GenerateUploadAuth GenerateUploadAuth update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:ListNetworkAccessPaths ListNetworkAccessPaths list

*NetworkAccessPath

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}/networkaccesspath/*

None None
eiam:ListFederatedCredentialProviders ListFederatedCredentialProviders list

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/*

None None
eiam:SetApplicationProvisioningScope SetApplicationProvisioningScope update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListEiamRegions ListEiamRegions none

*All Resource

*

None None
eiam:UpdateFederatedCredentialProviderDescription UpdateFederatedCredentialProviderDescription update

*FederatedCredentialProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}

None None
eiam:ListUsersForApplication ListUsersForApplication list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetApplicationProvisioningScope GetApplicationProvisioningScope get

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListAuthorizationRulesForUser ListAuthorizationRulesForUser list

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:DeleteApplicationFederatedCredential DeleteApplicationFederatedCredential delete

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}

None None
eiam:GetInstanceControlConfiguration GetInstanceControlConfiguration get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:EnableApplicationClientSecret EnableApplicationClientSecret update

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/{#SecretId}

None None
eiam:SetIdentityProviderUdPushConfiguration SetIdentityProviderUdPushConfiguration update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:DisableApplicationProvisioning DisableApplicationProvisioning update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DisableInternalAuthenticationSource DisableInternalAuthenticationSource update

*AuthenticationSource

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authenticationsource/{#AuthenticationSourceId}

None None
eiam:ListRegions ListRegions get

*All Resource

*

None None
eiam:ListApplicationTokens ListApplicationTokens list

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/*

None None
eiam:AddApplicationToAuthorizationRule AddApplicationToAuthorizationRule create

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:GetApplicationRole GetApplicationRole get

*ApplicationRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/{#ApplicationRoleId}

None None
eiam:DeleteGroup DeleteGroup delete

*Group

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}

None None
eiam:DisableConditionalAccessPolicy DisableConditionalAccessPolicy update

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}

None None
eiam:UpdateDomainBrand UpdateDomainBrand update

*Domain

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}

None None
eiam:ListConditionalAccessPoliciesForApplication ListConditionalAccessPoliciesForApplication list

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*

None None
eiam:ListGroupsForUser ListGroupsForUser get

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:CreateDomainProxyToken CreateDomainProxyToken create

*DomainProxyToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/*

None None
eiam:UpdateApplicationFederatedCredential UpdateApplicationFederatedCredential update

*ApplicationFederatedCredential

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}

None None
eiam:GetInstanceTrialStatus GetInstanceTrialStatus get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GenerateOauthToken GenerateOauthToken none

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:DisableApplicationSso DisableApplicationSso update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:EnableIdentityProviderAuthn EnableIdentityProviderAuthn update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:SetForgetPasswordConfiguration SetForgetPasswordConfiguration update

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GetInstance GetInstance get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:ListDomainProxyTokens ListDomainProxyTokens list

*DomainProxyToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/*

None None
eiam:GetBrand GetBrand get

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:UpdateUser UpdateUser update

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:GetRootOrganizationalUnit GetRootOrganizationalUnit get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:DisableCloudAccountRole DisableCloudAccountRole update

*CloudAccountRole

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/${#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}

None None
eiam:RemoveUserFromOrganizationalUnits RemoveUserFromOrganizationalUnits delete

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:UpdateIdentityProvider UpdateIdentityProvider update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:CreateApplicationToken CreateApplicationToken create

*ApplicationToken

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/*

None None
eiam:CreateResourceServerScope CreateResourceServerScope create

*ResourceServerScope

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/resourceserverscope/*

None None
eiam:AddUserToAuthorizationRule AddUserToAuthorizationRule create

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:GetIdentityProviderAdvancedConfiguration GetIdentityProviderAdvancedConfiguration get

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:SetApplicationSsoConfig SetApplicationSsoConfig create

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:CreateApplicationClientSecret CreateApplicationClientSecret create

*Secret

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/*

None None
eiam:EnableIdentityProviderAdvancedAbility EnableIdentityProviderAdvancedAbility update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None
eiam:DeleteUser DeleteUser delete

*User

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}

None None
eiam:UpdateBrand UpdateBrand update

*Brand

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}

None None
eiam:GetInstanceGlobalizationConfig GetInstanceGlobalizationConfig get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:DisableApplicationM2MClient DisableApplicationM2MClient update

*Application

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}

None None
eiam:ListConditionalAccessPolicies ListConditionalAccessPolicies list

*ConditionalAccessPolicy

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*

None None
eiam:SetPasswordHistoryConfiguration SetPasswordHistoryConfiguration get

*Instance

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}

None None
eiam:GetAuthorizationRule GetAuthorizationRule get

*AuthorizationRule

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}

None None

Resource

The following table lists the resources defined by Identity as a Service. Specify them in the Resource element of RAM policy statements to grant permissions for specific operations. They are uniquely identified by ARNs. Format: acs:{#ramcode}:{#regionId}:{#accountId}:{#resourceType}:

  • acs: The initialism of Alibaba Cloud service, which indicates the public cloud of Alibaba Cloud.

  • {#ramcode}: The code used in RAM to indicate an Alibaba Cloud service.

  • {#regionId}: The region ID. If the resource covers all regions, set it to an asterisk (*).

  • {#accountId}: The ID of the Alibaba Cloud account. If the resource covers all Alibaba Cloud accounts, set it to an asterisk (*).

  • {#resourceType}: The service-defined resource identifier. It supports a hierarchical structure, which is similar to a file path. If the statement covers global resources, set it to an asterisk (*).

Resource type

ARN

FederatedCredentialProvider
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/{#FederatedCredentialProviderId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/federatedcredentialprovider/*
Instance
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}
  • acs:eiam:{#regionId}:{#accountId}:instance/*
ApplicationFederatedCredential
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/{#ApplicationFederatedCredentialId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/*/applicationfederatedcredential/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationfederatedcredential/*
IdentityProvider
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/*
User
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/*
ApplicationToken
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/{#ApplicationTokenId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationtoken/*
Group
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/group/{#GroupId}
Application
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/*
OrganizationalUnit
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/{#OrganizationalUnitId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/organizationalunit/*
CustomPrivacyPolicy
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#CustomPrivacyPolicyId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/{#PolicyId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/*
ConditionalAccessPolicy
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/{#ConditionalAccessPolicyId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/conditionalaccesspolicy/*
ResourceServerScope
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/resourceserverscope/{#ResourceServerScopeId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/resourceserverscope/*
ApplicationTemplate
  • acs:eiam:{#regionId}:{#accountId}:applicationtemplate/{#ApplicationTemplateId}
Secret
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/{#SecretId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/secret/*
Brand
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/brand/{#BrandId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customprivacypolicy/*
NetworkZone
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/{#NetworkZoneId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkzone/*
Domain
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}
SynchronizationJob
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/synchronizationjob/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/synchronizationjob/{#SynchronizationJobId}
AuthorizationRule
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationRule/{#AuthorizationRuleId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/AuthorizationRule/{#AuthorizationRuleId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/*
CloudAccount
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}
ApplicationAccount
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationaccount/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationaccount/{#ApplicationAccountId}
NetworkAccessEndpoint
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}
CustomField
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/{#FieldId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/customfield/*
CloudAccountRole
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}/cloudaccountrole/*
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/${#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/cloudaccount/{#CloudAccountId}/cloudaccountrole/{#CloudAccountRoleId}
ClientPublicKey
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/{#ClientPublicKeyId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/clientpublickey/*
DomainProxyToken
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/{#DomainProxyTokenId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/domain/{#DomainId}/domainproxytoken/*
AuthenticationSource
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authenticationsource/{#AuthenticationSourceId}
ApplicationRole
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/{#ApplicationRoleId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/application/{#ApplicationId}/applicationrole/*
AuthorizationResource
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}/authorizationresource/{#AuthorizationResourceId}
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/authorizationrule/{#AuthorizationRuleId}/authorizationresource/*
Authenticator
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/user/{#UserId}/authenticator/{#AuthenticatorId}
NetworkAccessPath
  • acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/networkaccessendpoint/{#NetworkAccessEndpointId}/networkaccesspath/*

Condition

Identity as a Service does not define product-level condition keys. However, you can use Alibaba Cloud common condition keys for access control. For more information, see Common condition keys.

How to create custom RAM policies?

You can create custom policies and grant them to RAM users, RAM user groups, or RAM roles. For instructions, see: