Revoke RAM user group permissions
When a RAM user group no longer needs certain permissions, you can revoke them from the Groups page or the Grants page.
After you revoke permissions from a RAM user group, RAM users in that group can no longer access the associated resources. Make sure this change is expected before you proceed.
Method 1: Use the Groups page
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
On the Groups page, click the name of the RAM user group you want.
-
Click the Permissions tab, find the target policy, and then click Revoke Permission in the Actions column.
-
In the Revoke Permission dialog box, click Revoke Permission.
Method 2: Use the Grants page
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
On the Grants page, find the permission that you want to revoke and click Revoke Permission in the Actions column.
Alternatively, to revoke multiple permissions at once, select their corresponding checkboxes and click Revoke Permission at the bottom of the list.
-
In the Revoke Permission dialog box, click Revoke Permission.