Limitations

Updated at:

Resource Access Management (RAM) enforces quota limits on the entities that you create and the policies that you attach. This topic lists the RAM quota limits and how to request a quota increase, and describes how to handle exceeded policy limits.

CategoryLimit itemMaximum valueQuota increase method
RAM userNumber of RAM users in an Alibaba Cloud account5000Not adjustable
Number of characters in a RAM username64Not adjustable
Number of user groups to which a RAM user can be added10Not adjustable
Number of AccessKey pairs that can be created for a RAM user2Not adjustable
Number of multi-factor authentication devices that can be bound to a RAM user1Not adjustable
Number of system policies that can be attached to a RAM user20Apply for a quota increase
Number of custom policies that can be attached to a RAM user10Apply for a quota increase
Number of tags that can be bound to a RAM user20Not adjustable
RAM user groupNumber of RAM user groups in an Alibaba Cloud account300Not adjustable
Number of characters in a RAM user group name64Not adjustable
Number of system policies that can be attached to a RAM user group20Apply for a quota increase
Number of custom policies that can be attached to a RAM user group10Apply for a quota increase
RAM roleNumber of RAM roles in an Alibaba Cloud account1000Apply for a quota increase
Number of characters in a RAM role name64Not adjustable
Number of system policies that can be attached to a RAM role20 (can be increased to 40)Apply for a quota increase
Number of custom policies that can be attached to a RAM role10 (can be increased to 20)Apply for a quota increase
Default domain nameNumber of characters in a default domain name, including the suffix64Not adjustable
Access policyNumber of characters in an access policy name128Not adjustable
Multi-factor authenticationNumber of virtual MFA devices or U2F security keys (Universal 2nd Factor devices) that can be created in an Alibaba Cloud account5000Not adjustable
Number of RAM users that can be bound to a secure phone number5Not adjustable
Number of RAM users that can be bound to a security email address5Not adjustable
Custom policyNumber of custom policies that can be created in an Alibaba Cloud account1500Apply for a quota increase
Number of characters in a custom policy6144Not adjustable
Number of versions of a custom policy5Not adjustable
Identity providerNumber of SAML IdPs that can be created in an Alibaba Cloud account100Not adjustable
Number of IdPs that can be included in a SAML IdP1Not adjustable
Number of certificates that can be included in an IdP of a SAML IdP2Not adjustable
Number of OpenID Connect (OIDC) IdPs that can be created in an Alibaba Cloud account100Not adjustable
Number of client IDs in an OIDC IdP20Not adjustable
Number of fingerprints in an OIDC IdP5Not adjustable
Note
  • The number of policies that can be attached to a RAM user, RAM user group, or RAM role is independent of the authorization scope. The policy quota for authorization within a single resource group is the same as the quota for authorization across the entire Alibaba Cloud account. The two quotas are counted separately and do not consume each other.

  • RAM roles whose names start with AliyunReservedSSO are the RAM roles that Cloud Single Sign-On (CloudSSO) uses when it deploys an access configuration. The numbers of custom policies and system policies that can be attached to these RAM roles (access configurations) are centrally configured in CloudSSO. For more information, see Limitations.

Handle exceeded policy limits

If the number of policies attached to a RAM user, RAM user group, or RAM role reaches the limit, or the content of a custom policy exceeds the character limit, use the following methods. Apply for a quota increase first for the limits that support it, and merge or shorten policies when the increase is not enough or the limit cannot be adjusted.

  • Increase the quota: Go to Quota Center, search for "Number of system policies that can be attached to a RAM role" or "Number of custom policies that can be attached to a RAM role", and submit a quota increase request. You can increase the system policy limit from 20 to 40 and the custom policy limit from 10 to 20.

  • Merge policies: On the policy management page of the RAM console, click Create Policy, switch to Script edit mode, and merge the Actions of multiple system policies into one custom policy. You can use wildcards such as oss:Get* to simplify the Action list and reduce the number of characters.

    If a quota increase is still not enough, for example, when the number of read-only system policies that you need exceeds the increased limit, merge policies to further reduce the number of policy slots used. For example, merge the read-only permissions of API Gateway, Data Transmission Service (DTS), and Auto Scaling (ESS) into one custom policy:

    {
      "Version": "1",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "apigateway:Describe*",
            "apigateway:List*",
            "dts:Describe*",
            "dts:List*",
            "ess:Describe*",
            "ess:List*"
          ],
          "Resource": "*"
        }
      ]
    }

    This example consolidates the read-only permissions of three services into one custom policy, which saves two policy slots compared with attaching three read-only system policies separately. The number of services that one custom policy can consolidate is not fixed. It is constrained by the character limit on the content of a custom policy, so evaluate it against the actual length of your Action list.

  • Handle the character limit: The content of a custom policy cannot exceed 6,144 characters, and this limit cannot be adjusted. If the merged content still exceeds the limit, split it into multiple custom policies, or use wildcards instead of specific Action names to shorten the content.

  • Coverage of ReadOnlyAccess: The system policy AliyunReadOnlyAccess uses wildcards such as *:Describe*, *:List*, *:Get*, and *:Read* to cover most read-only operations. Actions that do not follow these naming conventions, such as hbr:BrowseFiles, alikafka:DashboardList, actiontrail:Lookup*, dm:Desc*, and hbr:Search*, are not covered automatically and must be added separately to a custom policy.

  • Use a single all-product read-only policy instead of one read-only policy per product: To grant a RAM user read-only permissions on all Alibaba Cloud products, attach the AliyunReadOnlyAccess system policy. For example, you do not need to separately attach the OSS and ECS read-only system policies AliyunOSSReadOnlyAccess and AliyunECSReadOnlyAccess. Attaching one policy per product quickly consumes the system policy quota, which is 20 system policies per RAM user. After the limit is reached, attaching another policy returns the LimitExceeded.User.Policy error. The single AliyunReadOnlyAccess policy covers the read-only operations of most Alibaba Cloud products and occupies only one system policy slot.