Resource Group provides the Use Creator as Administrator feature. You can enable or disable this feature based on your business requirements. After you enable this feature, the creator of a resource group is automatically granted the AdministratorAccess permission on the resource group and becomes the administrator of the resource group. The creator can create and manage resources in the resource group. After you disable this feature, the creator of a resource group is not automatically granted permissions. If the creator wants to create and manage resources in the resource group, the creator must be manually granted the required permissions. This feature is enabled by default.
Usage notes
The feature affects the permissions only of RAM identities (RAM users or RAM roles) that are used to create resource groups. By default, an Alibaba Cloud account has all permissions on resources within the account. Therefore, the permissions of Alibaba Cloud accounts are not affected.
The feature takes effect for all RAM identities within your Alibaba Cloud account.
After you enable or disable the feature, the authorization of existing resource groups is not affected.
Enable the Use Creator as Administrator feature
Impact
After you enable the Use Creator as Administrator feature, if you create a resource group by using a RAM identity, the RAM identity is automatically granted the AdministratorAccess permission on the resource group. This indicates that the RAM identity becomes the administrator of the resource group and can be used to create and manage resources in the resource group.
Procedure
Log on to the Resource Management console.
In the left-side navigation pane, choose
.In the Use Creator as Administrator section, click Enable.
In the Enable dialog box, click OK.
Disable the Use Creator as Administrator feature
Impact
After you disable the Use Creator as Administrator feature, if you create a resource group by using a RAM identity, the RAM identity is not automatically granted the AdministratorAccess permission on the resource group. If you want to create and manage resources in the resource group by using the RAM identity, you need to manually grant the required permissions on the resource group to the RAM identity.
Procedure
Log on to the Resource Management console.
In the left-side navigation pane, choose
.In the Use Creator as Administrator section, click Disable.
In the Disable dialog box, click OK.