RAM users can log on to the Alibaba Cloud Management Console with a username and password, a passkey, or a DingTalk account.
RAM user logon entry points
RAM provides multiple logon entry points. Choose the one that best suits your needs.
General entry: Go to the RAM User Logon page, or go to the Alibaba Cloud account logon page and click RAM Logon.
Dedicated entry (Recommended): If you know your company's default logon suffix (for example,
@company-alias.onaliyun.com), you can use a dedicated link to go directly to your company's logon page. This saves you from entering the suffix manually. For more information about how to view and change your logon suffix, see Manage the logon settings for a RAM user.URL format:
https://signin.aliyun.com/<your-default-logon-suffix>/login.htmLog on to the RAM console with your Alibaba Cloud account. On the Overview page, you can find the RAM user logon URL and share it with other users.
RAM user-specific logon URL (Recommended): Specify
username=RAM-username@<your-default-logon-suffix>in the logon URL to pre-fill the username field. Then, click Next and enter your password.URL format:
https://signin.aliyun.com/login.htm?username=RAM-username@<your-default-logon-suffix>
Method 1: Log on with a username and password
To log on from the general logon entry point, follow these steps.
Go to the RAM User Logon page.
On the RAM User Logon tab, enter your username and click Next. The username is typically in one of the following formats:
<RAM-username>@<default-logon-suffix>or<RAM-username>@<custom-logon-suffix>. For more information about how to view and change your logon suffixes, see Manage the logon settings for a RAM user.Enter your password and click Log On.
NoteIf the system detects that your password is weak when you log on, you are redirected to a password reset page. We recommend that you change it to a stronger password. You can skip this step without affecting the current logon. For more information, see the announcement.
If the system detects that your password is weak when you log on, you are redirected to a password reset page. We recommend that you change it to a stronger password. You can skip this step without affecting the current logon. For more information, see the announcement.
(Optional) If you have enabled multi-factor authentication (MFA), you must also complete MFA verification. For more information, see Multi-factor authentication (MFA) and Enable an MFA device for a RAM user.
Method 2: Log on with a passkey
A passkey provides a secure, password-free way to log on by verifying your identity with your device's built-in security features, such as a fingerprint, face scan, or PIN.
Prerequisites
Enabled by an administrator: A RAM administrator must allow RAM users to log on with a passkey in the global security settings. By default, Alibaba Cloud has this option enabled for Alibaba Cloud accounts. To change this setting:
Log on to the RAM console by using an Alibaba Cloud account or as a RAM user with RAM administrator permissions (the
AliyunRAMFullAccesspolicy).On the Settings page, in the Security section, click Modify.
In the Global Security dialog box, enable Allow users to login with passkey.
Registered by the user: You must have registered a passkey, such as Touch ID or Windows Hello, in your personal security settings. For more information, see Manage passkeys for a RAM user.
Procedure
Go to the RAM User Logon page.
On the RAM User Logon tab, enter your username and click Next. The username is typically in one of the following formats:
<RAM-username>@<default-logon-suffix>or<RAM-username>@<custom-logon-suffix>. For more information about how to view and change your logon suffixes, see Manage the logon settings for a RAM user.Click Passkey Logon. If passkey logon fails, you can click Logon Using Password to use your password instead.
Your browser displays a security prompt for verification. If you registered multiple passkeys, select the one that you want to use.
After completing the verification, you are logged on.
Method 3: Log on with a DingTalk account
If your RAM user is linked to a DingTalk account, you can log on by scanning a QR code with the DingTalk app without needing a password. To learn how to link a DingTalk account to a RAM user, see Link or unlink a DingTalk account for a RAM user.
QR code logon
On the RAM User Logon page, click the DingTalk QR Code tab.
Open the DingTalk app on your mobile device and scan the QR code.
In the DingTalk app, tap Log on to Alibaba Cloud RAM on the web.
On the RAM User DingTalk QR Code Logon page in your browser, review the RAM user information that is linked to your DingTalk account, and then click Log On.
NoteIf your DingTalk account is linked to multiple RAM users, you must select the user that you want to use from the list before you log on.
One-click logon
When you open an Alibaba Cloud link in the DingTalk mobile app, such as a web link in a chat, you can use the one-click logon feature. If the page requires you to log on as a RAM user, tap Log in with DingTalk. This action logs you on as the RAM user that is linked to your DingTalk account, without entering a username or password. If your DingTalk account is linked to multiple RAM users, you must select the one you want to use from a list.
FAQ
What if a RAM user forgets their password?
Contact a RAM administrator to reset your password. For security reasons, RAM users cannot reset their own passwords. For more information, see Change the logon password of a RAM user.
What do I do if the error "This account does not allow RAM user logon" appears?
This error usually means that console logon has not been enabled for the RAM user. To resolve this issue, an administrator (the Alibaba Cloud account owner or a RAM user with RAM management permissions) must enable console logon for the affected user:
Log on to the RAM console.
In the left-side navigation pane, choose Identities > Users.
Click the username of the target user.
On the Authentication tab, in the Console Logon Management section, click Modify Logon Settings.
Turn on Console Access and set a logon password for the user.
RAM users must log on with the full username format <RAM-username>@<default-logon-suffix> or <RAM-username>@<custom-logon-suffix>, and the password set by the administrator. Do not use a personal phone number to log on. For more information about logon suffixes, see Manage RAM user logon domains.
How do I troubleshoot RAM user logon anomalies or display issues?
If you encounter logon anomalies or display issues, try the following solutions based on your scenario:
After logging on, the console automatically switches to the Alibaba Cloud account (primary account): This is typically caused by browser session conflicts. Log out of the primary account first, and then log on as the RAM user. Alternatively, use a different browser or open an incognito or private browsing window.
After logging on, the console shows a personal account status and enterprise resources are not visible: Check the following in the RAM console:
Verify that the Alibaba Cloud account (primary account) has completed the required verification.
Check whether multi-factor authentication (MFA) is properly configured for the RAM user.
The logon dialog box does not appear or displays as a gray window: Check the following:
Verify that the RAM username is correct and that console access has been enabled for the user.
Use a supported browser such as Google Chrome or Microsoft Edge.
Check whether your network uses a proxy that may be blocking access to the logon page.
Other common questions about RAM user logon
Can a RAM user log on from multiple devices at the same time?
Yes. Alibaba Cloud does not limit the number of concurrent logon sessions for a RAM user. You can log on to the Alibaba Cloud Management Console from multiple computers or devices at the same time.
Do I need a phone verification code to log on to the Alibaba Cloud mobile app?
Yes. You currently need to receive an SMS verification code on the security phone number that is bound to your account for identity verification.
Is there any risk in skipping MFA verification?
You can choose to skip multi-factor authentication (MFA) verification during logon. However, skipping MFA reduces the security of your account. We recommend that you enable MFA. For more information, see Multi-factor authentication (MFA) and Bind an MFA device for a RAM user.
What do I do if a RAM user is blocked from logging on due to security restrictions?
If a RAM user account is restricted from logging on due to a security risk such as an AccessKey leak, you must apply to have the restriction lifted. After the request is verified and processed, refresh the logon page to resume normal access.
After the restriction is lifted, immediately check and rotate any compromised AccessKey pairs to protect your account. You can manage AccessKey pairs in the RAM console.