Revoke a RAM identity's resource group permissions

更新时间:
复制 MD 格式

This topic describes how to revoke operation permissions on resources in a resource group from a RAM user or role.

Prerequisites

An Alibaba Cloud account or a RAM identity (RAM user or RAM role) that has the permissions to manage resource group authorization is prepared.

Procedure

You can revoke permissions in the Resource Management or RAM console. In this example, the Resource Management console is used.

  1. Log on to the Resource Management console. The Resource Group page appears.

  2. On the Resource Group page, find the resource group you want and click Permissions in the Actions column.

  3. In the list of permissions, find the permission that you want to revoke and click Remove Authorization in the Actions column.

    Note

    You can also select multiple permissions and click Remove Authorization at the bottom of the list to revoke them at once.

  4. In the Remove Authorization dialog box, click Remove Authorization.

Result

After the permission is revoked, the RAM user or role does not have the operation permission on resources in the resource group.

References

For information about how to remove permissions in the RAM console, see Remove permissions from a RAM user, Remove permissions from a RAM user group, and Remove permissions from a RAM role.