检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
For details about how to obtain the project ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. Ensure that the project is the IAM project that IAM users in the group will be authorized to access and use.
Prerequisites Before creating a user group, learn about the following: Basic concepts of permissions System-defined permissions provided by IAM Creating a User Group Log in to the IAM console as the administrator.
Table 14 token.assumed_by.user Parameter Type Description name String IAM username. id String IAM user ID. domain Object Account information about delegated party B. password_expires_at String Password expiration time of the IAM user.
Identity Providers Overview Application Scenarios of Virtual User SSO and IAM User SSO Virtual User SSO via SAML IAM User SSO via SAML Virtual User SSO via OpenID Connect Syntax of Identity Conversion Rules
Constraints An IAM user can have to only one virtual MFA device added. An IAM user can have a maximum of eight security keys added. Parent topic: MFA Authentication
Only the administrator can configure the ACL to control access of all IAM users under the account from specific IP address ranges, CIDR blocks, or VPC endpoints.
User Group Management Overview Creating a User Group and Assigning Permissions Adding IAM Users to or Removing IAM Users from a User Group Deleting User Groups Managing User Group Information Managing Permissions of a User Group Assigning Dependency Roles
Procedure Use the DomainA account to create an IAM user (for example, UserB) by following the instructions in Creating an IAM User.
For IAM endpoints, see Regions and Endpoints. Debugging You can debug this API in API Explorer.
Feature Description Phase Document 1 Changing the access type of IAM users The administrator can change the access type of an IAM user on the Basic Information page.
You can configure identity conversion rules on the IAM console to achieve the following: Display enterprise users with different names in Huawei Cloud. Assign permissions to enterprise users to use Huawei Cloud resources by mapping these users to IAM user groups.
Passwords and Credentials What Should I Do If I Forgot the Password of an IAM User or Account? How Do I Change the Password of an IAM User or Account? How Do I Obtain an Access Key (AK/SK)? What Should I Do If I Have Forgotten My Access Key (AK/SK)?
Deleting User Groups Procedure To delete a user group, do the following: Log in to the IAM console. In the navigation pane, choose User Groups. In the user group list, click Delete in the row that contains the user group to be deleted.
For IAM endpoints, see Regions and Endpoints. Debugging You can debug this API in API Explorer.
", "name": "IAMAgency", "agency_urn": "iam::d78cbac186b744899480f25b...8:agency:IAMAgency", "trust_domain_id": "a2cd82a33fb043dc9304bf72...
If you do not a password for logging in to the management console, request the administrator to create an access key for you on the IAM console. For details, see Managing Access Keys for an IAM User. Parent topic: Passwords and Credentials
Log in to the IAM console as the administrator. On the IAM console, choose Agencies from the navigation pane on the left, and click Create Agency on the displayed page. Enter an agency name.
This condition must be used together with g:MFAPresent. g:ProjectName String Project name. g:UserId String IAM user ID. g:UserName String IAM username. (Optional) Switch to the JSON view and modify the policy content in JSON format.
For details about how to obtain the account ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. group_id Yes String User group ID.
For details about how to obtain a user group ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. project_id Yes String Project ID.