Logon method | Description | Applicable member type | References |
Use a RAM user of the management account of a resource directory to assume the RAM role of a member in the resource directory and log on to the Alibaba Cloud Management Console | The system automatically creates a RAM role named ResourceDirectoryAccountAccessRole for each member in a resource directory and specifies the management account of the resource directory as the trusted entity for the RAM role. This way, the management account has permissions to assume the RAM roles of all members in the resource directory and log on to the Alibaba Cloud Management Console. You can use the management account of a resource directory to create a RAM user and grant administrative permissions to the RAM user. Then, you can use the RAM user to assume the RAM role ResourceDirectoryAccountAccessRole of a member in the resource directory and log on to the Alibaba Cloud Management Console. | Members that are created in a resource directory. Members that are created in a resource directory are of the resource account type. They have usernames but do not have logon passwords. Alibaba Cloud accounts that are invited to join a resource directory as members. These members are of the cloud account type.
| Use a RAM role to log on to the Alibaba Cloud Management Console |
Use a RAM user created for a member to log on to the Alibaba Cloud Management Console | After you use a RAM user of the management account of a resource directory to assume the RAM role of a member in the resource directory and log on to the Alibaba Cloud Management Console, you can create a RAM user for the member and grant the required permissions to the RAM user. Then, you can log on to the Alibaba Cloud Management Console as the RAM user created for the member. | Log on to the Alibaba Cloud Management Console as a RAM user |
Use the root user of a member to log on to the Alibaba Cloud Management Console (not recommended) | If you want to use a member of the cloud account type in a resource directory to log on to the Alibaba Cloud Management Console, you can use the username and password of the root user of the member. However, for security purposes, we recommend that you do not use this method. | Alibaba Cloud accounts that are invited to join a resource directory as members. These members are of the cloud account type. | Log on to the Alibaba Cloud Management Console as the root user of a member |
Use a CloudSSO user to log on to the Alibaba Cloud Management Console | CloudSSO is integrated with Alibaba Cloud Resource Directory to help you manage identities and access permissions for multiple accounts in a centralized manner. After you activate CloudSSO and grant access permissions on a member in a resource directory to the CloudSSO user, the CloudSSO user can log on to the CloudSSO user portal and access resources of the member based on the related access configuration. | CloudSSO users. | Use CloudSSO to manage the identities and permissions of multiple accounts of an enterprise in a centralized manner |