检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Log in to the management console as the IAM user. If resource information is displayed, the IAM user has been successfully assigned the required permissions. Figure 5 My Resources Parent topic: FAQs
Solution You can enable login protection for the noncompliant IAM users. For more details, see Login Protection. Rule Logic If an IAM user is in the disabled state, this user is compliant. If an IAM user that is enabled has MFA enabled, this user is compliant.
This section describes how to use IAM to implement fine-grained permissions control for your VPC resources. With IAM, you can: Create IAM users for personnel based on your enterprise's organizational structure.
If your account does not require individual IAM users for permissions management, you can skip this section. IAM is a free service. You only pay for the resources in your account. For more information about IAM, see IAM Service Overview.
Figure 4 Selecting Identity and Access Management Grant the admin or Full Access permission to the IAM user. Once done, the IAM user can view service monitoring data.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see IAM Service Overview. VBS Permissions By default, new IAM users do not have permissions assigned.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see IAM Service Overview. VBS Permissions By default, new IAM users do not have permissions assigned.
Characteristics of User Groups A user group can contain multiple IAM users, and an IAM user can be added to multiple user groups. User groups cannot be nested. They can only contain IAM users, not other user groups. By default, each account has only one preset admin user group.
Grants the permission to associate the IAM agency with a role. iam:roles:createRole Grants the permission to create an IAM agency role. iam:agencies:deleteAgency Grants the permission to delete an IAM agency.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see IAM Service Overview. CSBS Permissions By default, new IAM users do not have permissions assigned.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see IAM Service Overview. CSBS Permissions By default, new IAM users do not have permissions assigned.
For example, the endpoint of IAM in region CN-Hong Kong is iam.ap-southeast-1.myhuaweicloud.com.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see What Is IAM? HSS Permissions By default, new IAM users do not have permissions assigned.
You can use IAM to securely control access to your SFS Turbo resources. Table 1 SFS Turbo access control Method Description Reference Permissions control IAM permissions IAM permissions define which actions on your cloud resources are allowed or denied.
With IAM, you can: Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials, providing access to DRS resources. Grant only the permissions required for users to perform a specific task.
Table 3 Dependency policies and roles Console Function Dependent Services Roles or Policies Required OBS authorization Identity and Access Management (IAM) Creating an agency: iam:agencies:createAgency Listing agencies: iam:agencies:listAgencies Querying agency details: iam:agencies
IAM User IAM users can bind a virtual MFA device on the IAM console. The procedure is the same as that for binding a virtual MFA device for a Huawei Cloud account.
For example, to obtain an IAM token in the CN-Hong Kong region, obtain the endpoint of IAM (iam.ap-southeast-1.myhuaweicloud.com) for this region and the resource-path (/v3/auth/tokens) in the URI of the API used to obtain a user token.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see the IAM Service Overview. DCS Permissions By default, new IAM users do not have permissions assigned.
If your account does not need individual IAM users for permissions management, you can skip this section. IAM is a free service. You pay only for the resources in your account. For more information about IAM, see IAM Service Overview.