All Products
Search
Document Center

Resource Management:Revoke resource group-based permissions from a RAM identity

Last Updated:Nov 24, 2025

This topic describes how to revoke operation permissions on resources in a resource group from a RAM user or role.

Prerequisites

An Alibaba Cloud account or a RAM identity (RAM user or RAM role) that has the permissions to manage resource group authorization is prepared.

Procedure

You can revoke permissions in the Resource Management or RAM console. In this example, the Resource Management console is used.

  1. Log on to the Resource Management console. The Resource Group page appears.

  2. On the Resource Group page, find the desired resource group and click Manage Permission in the Actions column.

  3. On the Permissions tab, find the permission that you want to revoke and click Revoke Permission in the Actions column.

    image

    Note

    You can select multiple permissions at a time and click Revoke Permission in the lower part to batch revoke permissions.

  4. In the Revoke Permission dialog box, click Revoke Permission.

Result

After the permission is revoked, the RAM user or role does not have the operation permission on resources in the resource group.

References

For information about how to remove permissions in the RAM console, see Remove permissions from a RAM user, Remove permissions from a RAM user group, and Remove permissions from a RAM role.