Limitations
Resource Access Management (RAM) enforces quota limits on the entities that you create and the policies that you attach. This topic lists the RAM quota limits and how to request a quota increase, and describes how to handle exceeded policy limits.
| Category | Limit item | Maximum value | Quota increase method |
| RAM user | Number of RAM users in an Alibaba Cloud account | 5000 | Not adjustable |
| Number of characters in a RAM username | 64 | Not adjustable | |
| Number of user groups to which a RAM user can be added | 10 | Not adjustable | |
| Number of AccessKey pairs that can be created for a RAM user | 2 | Not adjustable | |
| Number of multi-factor authentication devices that can be bound to a RAM user | 1 | Not adjustable | |
| Number of system policies that can be attached to a RAM user | 20 | Apply for a quota increase | |
| Number of custom policies that can be attached to a RAM user | 10 | Apply for a quota increase | |
| Number of tags that can be bound to a RAM user | 20 | Not adjustable | |
| RAM user group | Number of RAM user groups in an Alibaba Cloud account | 300 | Not adjustable |
| Number of characters in a RAM user group name | 64 | Not adjustable | |
| Number of system policies that can be attached to a RAM user group | 20 | Apply for a quota increase | |
| Number of custom policies that can be attached to a RAM user group | 10 | Apply for a quota increase | |
| RAM role | Number of RAM roles in an Alibaba Cloud account | 1000 | Apply for a quota increase |
| Number of characters in a RAM role name | 64 | Not adjustable | |
| Number of system policies that can be attached to a RAM role | 20 (can be increased to 40) | Apply for a quota increase | |
| Number of custom policies that can be attached to a RAM role | 10 (can be increased to 20) | Apply for a quota increase | |
| Default domain name | Number of characters in a default domain name, including the suffix | 64 | Not adjustable |
| Access policy | Number of characters in an access policy name | 128 | Not adjustable |
| Multi-factor authentication | Number of virtual MFA devices or U2F security keys (Universal 2nd Factor devices) that can be created in an Alibaba Cloud account | 5000 | Not adjustable |
| Number of RAM users that can be bound to a secure phone number | 5 | Not adjustable | |
| Number of RAM users that can be bound to a security email address | 5 | Not adjustable | |
| Custom policy | Number of custom policies that can be created in an Alibaba Cloud account | 1500 | Apply for a quota increase |
| Number of characters in a custom policy | 6144 | Not adjustable | |
| Number of versions of a custom policy | 5 | Not adjustable | |
| Identity provider | Number of SAML IdPs that can be created in an Alibaba Cloud account | 100 | Not adjustable |
| Number of IdPs that can be included in a SAML IdP | 1 | Not adjustable | |
| Number of certificates that can be included in an IdP of a SAML IdP | 2 | Not adjustable | |
| Number of OpenID Connect (OIDC) IdPs that can be created in an Alibaba Cloud account | 100 | Not adjustable | |
| Number of client IDs in an OIDC IdP | 20 | Not adjustable | |
| Number of fingerprints in an OIDC IdP | 5 | Not adjustable |
The number of policies that can be attached to a RAM user, RAM user group, or RAM role is independent of the authorization scope. The policy quota for authorization within a single resource group is the same as the quota for authorization across the entire Alibaba Cloud account. The two quotas are counted separately and do not consume each other.
RAM roles whose names start with
AliyunReservedSSOare the RAM roles that Cloud Single Sign-On (CloudSSO) uses when it deploys an access configuration. The numbers of custom policies and system policies that can be attached to these RAM roles (access configurations) are centrally configured in CloudSSO. For more information, see Limitations.
Handle exceeded policy limits
If the number of policies attached to a RAM user, RAM user group, or RAM role reaches the limit, or the content of a custom policy exceeds the character limit, use the following methods. Apply for a quota increase first for the limits that support it, and merge or shorten policies when the increase is not enough or the limit cannot be adjusted.
Increase the quota: Go to Quota Center, search for "Number of system policies that can be attached to a RAM role" or "Number of custom policies that can be attached to a RAM role", and submit a quota increase request. You can increase the system policy limit from 20 to 40 and the custom policy limit from 10 to 20.
Merge policies: On the policy management page of the RAM console, click Create Policy, switch to Script edit mode, and merge the Actions of multiple system policies into one custom policy. You can use wildcards such as
oss:Get*to simplify the Action list and reduce the number of characters.If a quota increase is still not enough, for example, when the number of read-only system policies that you need exceeds the increased limit, merge policies to further reduce the number of policy slots used. For example, merge the read-only permissions of API Gateway, Data Transmission Service (DTS), and Auto Scaling (ESS) into one custom policy:
{ "Version": "1", "Statement": [ { "Effect": "Allow", "Action": [ "apigateway:Describe*", "apigateway:List*", "dts:Describe*", "dts:List*", "ess:Describe*", "ess:List*" ], "Resource": "*" } ] }This example consolidates the read-only permissions of three services into one custom policy, which saves two policy slots compared with attaching three read-only system policies separately. The number of services that one custom policy can consolidate is not fixed. It is constrained by the character limit on the content of a custom policy, so evaluate it against the actual length of your Action list.
Handle the character limit: The content of a custom policy cannot exceed 6,144 characters, and this limit cannot be adjusted. If the merged content still exceeds the limit, split it into multiple custom policies, or use wildcards instead of specific Action names to shorten the content.
Coverage of ReadOnlyAccess: The system policy
AliyunReadOnlyAccessuses wildcards such as*:Describe*,*:List*,*:Get*, and*:Read*to cover most read-only operations. Actions that do not follow these naming conventions, such ashbr:BrowseFiles,alikafka:DashboardList,actiontrail:Lookup*,dm:Desc*, andhbr:Search*, are not covered automatically and must be added separately to a custom policy.Use a single all-product read-only policy instead of one read-only policy per product: To grant a RAM user read-only permissions on all Alibaba Cloud products, attach the
AliyunReadOnlyAccesssystem policy. For example, you do not need to separately attach the OSS and ECS read-only system policiesAliyunOSSReadOnlyAccessandAliyunECSReadOnlyAccess. Attaching one policy per product quickly consumes the system policy quota, which is 20 system policies per RAM user. After the limit is reached, attaching another policy returns theLimitExceeded.User.Policyerror. The singleAliyunReadOnlyAccesspolicy covers the read-only operations of most Alibaba Cloud products and occupies only one system policy slot.