检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Policies that contain actions for both IAM and enterprise projects can be used and applied for both IAM and Enterprise Management. Policies that contain actions only for IAM projects can be used and applied to IAM only.
Preparations Preparing a Huawei Account Before using MgC, prepare a HUAWEI ID or an IAM user that can access MgC and obtain an AK/SK pair for the account or IAM user. For details about how to obtain an access key, see Preparations.
Service Overview Authorization Using IAM
Policies that contain actions for both IAM and enterprise projects can be used and applied for both IAM and Enterprise Management. Policies that contain actions only for IAM projects can be used and applied to IAM only.
Introduction You can use Identity and Access Management (IAM) for fine-grained permissions management of your EIP. If your HUAWEI ID does not need individual IAM users, you can skip this section. By default, new IAM users do not have permissions assigned.
Parent topic: IAM Identity Center
If your Huawei ID does not need individual IAM users, then you may skip over this section. By default, new IAM users do not have any permissions assigned. You need to add a user to one or more groups, and assign permissions policies to these groups.
Possible causes: Your IAM agency quota has been used up. On the Quotas page of the IAM console, check whether the agency quota has been used up. If yes, delete unnecessary agencies or submit a service ticket to increase the quota. You are an IAM user.
Prerequisites A Huawei Cloud account or IAM user that has passed real-name authentication is available. Parent topic: Tenant Management
Prerequisites A Huawei Cloud account or IAM user that has passed real-name authentication is available. Parent topic: Viewing Dashboards
During remote logins, you can select local, IAM, or admin login mode. In local or IAM login mode, use the accounts as required. In admin login mode, you can log in to a bastion host as user admin without entering passwords.
An IAM policy with the action element set to *:*:*, *:*, or * is of high security risk. Solution The administrator can modify noncompliant IAM policies or roles. For more details, see Modifying or Deleting a Custom Policy.
Using OBS Browser+ OBS Browser+ is a GUI client for easily managing data stored in OBS. It can be used on Windows 10, macOS, and Windows Server 2016. The following describes how to use basic functions on OBS Browser+, including creating a bucket (test-example-bucket as an example)
You can obtain the IAM username and IAM user's initial password from the administrator. In this example, the IAM username of the O&M personnel is Alice. IAM user password Password of the IAM user, rather than the account. Click Log In. The IAM user logs in to Huawei Cloud.
Regions for Using SCPs SCPs are available in the following regions: Regions for using SCPs also support the use of IAM identity policies.
This happens when your identity authentication on the IAM console fails. To resolve this problem, perform the following steps: Contact the security administrator of the tenant to log in to the IAM console. Check whether the user corresponding to the AK is disabled.
Operations Management (AOM) Application Operations Management (AOM) 16 Cloud Eye Cloud Eye (CES) 17 Application Performance Management (APM) Application Performance Management (APM) 18 IAM Identity Broker IAM Identity Broker User Support No.
Monitor the last login time of IAM users to identify accounts that have been inactive for an extended period. For such accounts, manage their identity credentials and permissions in a timely manner. Related cloud services and tools IAM Parent topic: SEC03 Permission Management
Solution Log in to IAM as an administrator. In the user list, click Authorize in the row that contains the target user. Figure 1 Authorizing an IAM user Set Authorization Model to RBAC.
For details, see Creating an IAM User and Granting Permissions. Parent topic: Permissions Management