You can control access to the service using an Alibaba Cloud account or a Resource Access Management (RAM) user. To allow a RAM user to use service features, you must use your Alibaba Cloud account to grant the required access policies to the RAM user.
Prerequisites
You have registered and logged in to an Alibaba Cloud account. For more information, see Account Management.
You have activated Multiexperience Development Platform EMAS. For more information, see Quick Start.
You have opened the Alibaba Cloud Management Console home page.
Procedure
Open the RAM console
On the Alibaba Cloud Management Console home page, hover over the profile picture in the upper-right corner to open the shortcut menu.
In the shortcut menu, select Resource Access Management to open the RAM console.

Create an entity
You can control access using a user, a user group, or a RAM role. Create the entity that meets your requirements.
On the Resource Access Management page, do the following:
Create a RAM user. For more information, see Create a RAM user.
Create a RAM user group. For more information, see Create a RAM user group.
Create a RAM role. For more information, see Overview of RAM roles.
Grant permissions
In the RAM console, choose Permission Management > Grant Permission to open the Grant Permission page.
On the Grant Permission page, click Add Permission to open the side panel.
In the side panel, configure the authorization settings. The following table describes the settings.
Option
Procedure
Authorization Scope
Select Entire Alibaba Cloud Account.
Principal
Enter a keyword to search for and select the user, user group, or RAM role that you created.
Select Permissions
Select the System Policy or Custom Policy tab.
Enter a keyword to search for system policies for cloud publishing and Multiexperience Development Platform (EMAS). These include the following:
AliyunMHubFullAccess: Grants full access to manage Multiexperience Development Platform (EMAS).
AliyunMHubReadOnlyAccess: Grants read-only access to Multiexperience Development Platform (EMAS).
AliyunEmasDevOpsFullAccess: Grants full access to manage cloud publishing.
AliyunEmasDevOpsReadOnlyAccess: Grants read-only access to cloud publishing.
Custom policies include the read permission for the added user list. For more information, see Create a read permission for the user list.
As needed, select the system policies for Multiexperience Development Platform (EMAS) and cloud publishing, and add them to the Selected list on the right.
ImportantSelect at least one system policy for Multiexperience Development Platform (EMAS).
Select at least one system policy for cloud publishing.
Click OK to save the settings.
Related content
Resource Access Management (RAM) is an Alibaba Cloud service. For more information, see Resource Access Management.