RAM user access

Updated at:

A Resource Access Management (RAM) user can log on to the Alibaba Cloud Link WAN console to manage your Internet of Things (IoT) networks. A RAM user can also use their AccessKey ID and AccessKey secret to call Alibaba Cloud Link WAN APIs.

First, you must create a RAM user and grant an authorization policy to the user. This allows the user to access Alibaba Cloud Link WAN. For more information about how to create a custom authorization policy, see Custom permissions.

Create a RAM user

If you already have a RAM user, you can skip these steps.

  1. Log on to the RAM console with your Alibaba Cloud account.
  2. In the left navigation pane, under Identity Management, click User.
  3. Click Create User.
  4. Login NameDisplay NameAccess ModeConsole AccessOpen API AccessEnter the user information: and . In the section, select or as needed.
  5. Console AccessIf you select , configure the password settings:
    1. For the Console Password, select Automatically Generate Password or Custom Password.
    2. Set Require Password Reset to User Must Reset Password At Next Logon or No Reset Required.
    3. Multi-factor Authentication (MFA)Enable MFADisable MFAFor , select or .
  6. Click OK.

After a RAM user is created, they can use the RAM user logon link to log on to Alibaba Cloud. The link is available on the Overview page of the RAM console.

However, the RAM user cannot access your cloud resources until you grant permissions. The next step is to grant the RAM user access to Alibaba Cloud Link WAN.

Grant a RAM user access to Alibaba Cloud Link WAN

In the RAM console, you can grant permissions to a single user or an entire user group on the Identity Management page. The following steps describe how to grant permissions to a single user.

  1. Log on to the RAM console with your Alibaba Cloud account.
  2. In the left navigation pane, under Identity Management, click Users.
  3. Find the RAM user to authorize and click the Add Authorization button.
  4. In the Add Permissions dialog box, search for and select the authorization policy that you want to grant to the user. Click the name of the access policy to move it to the Selected list. Then, click OK.
    Note Alibaba Cloud Link WAN provides two system policies: AliyunLinkWANFullAccess (permissions to manage Alibaba Cloud Link WAN) and AliyunLinkWANReadOnlyAccess (read-only access to Alibaba Cloud Link WAN). If you want to grant custom permissions to the RAM user, you must create an access policy first. For more information about how to create an access policy, see Custom permissions.

After the permissions are granted, the RAM user can access the resources and perform the operations defined in the access policy.

Log on to the console as a RAM user

You can use an Alibaba Cloud account to log on directly from the Alibaba Cloud homepage. A RAM user must log on from the RAM User Logon page.

  1. To obtain the URL for the RAM User Logon page, log on to the RAM console with your root account. On the Overview page, find the User Logon URL and distribute it to your RAM users.
  2. The RAM user visits the RAM User Logon page and logs on with their RAM username and password.
    Note The logon format for a RAM user is: `username@enterprise-alias`. For example, `username@company-alias`. The user must change their password after the first successful logon.
  3. In the upper-right corner of the page, click the Console button to open the Management Console.
  4. Click Products and Services and select Alibaba Cloud Link WAN to go to the Alibaba Cloud Link WAN console.

After the RAM user logs on to the Alibaba Cloud Link WAN console, they can perform operations according to their assigned permissions.