You can use the Control Policy feature only after you enable it.
Impact
After the Control Policy feature is enabled for a resource directory, the resource directory has the following changes:
The system automatically attaches the system access control policy FullAliyunAccess to folders and members in the resource directory. This policy allows all operations on all your cloud resources.
When you create a folder or member, the system automatically attaches the system access control policy FullAliyunAccess to the folder or member.
After an invited Alibaba Cloud account joins a resource directory, the system automatically attaches the system access control policy FullAliyunAccess to this member.
When you remove a member, the system automatically detaches all access control policies that are attached to this member.
Procedure
Log on to the Resource Management console.
In the left-side navigation pane, choose .
In the upper part of the Control Policy page, click Enable Control Policy.
In the Enable Control Policy message, click OK.
Click Refresh and view the status of the Control Policy feature.
What to do next
You can create a custom access control policy. For example, you can create a custom access control policy that is used to forbid an operation on a resource. Then, you can attach this policy to a folder or member in the resource directory to manage the operation permissions of members on this resource.