检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Creating a Virtual MFA Device Function This API is provided for IAM users to create a virtual MFA device. The API can be called using both the global endpoint and region-specific endpoints. For IAM endpoints, see Regions and Endpoints.
To grant an IAM user permission to access dependent cloud services of SWR, you must have the IAM role Security Administrator. Fine-grained HSS Authorization Log in to the management console.
Check whether your account is an IAM account. Ensure that your IAM account has the VPN FullAccess permission. For details, see Creating a User Group and Assigning Permissions and Adding Users to or Removing Users from a User Group. Parent topic: Account Permissions
If an IAM user is required to grant cluster namespace permissions to other users or user groups, the user must have the IAM read-only permission.
Creating an Enterprise Project Create user group Test_EPS and IAM user Test_EPS_User, and add the IAM user to the user group. Then create enterprise project Test_EPS_Project. For details, see Getting Started with Enterprise Management.
Error Reported When a DB Instance Is Purchased Scenario When an IAM user purchases an RDS DB instance, an error message is displayed, indicating that the user is not granted the IAM agency permission.
Error Reported When a DB Instance Is Purchased Scenario When an IAM user purchases an RDS DB instance, an error message is displayed, indicating that the user is not granted the IAM agency permission.
Applicable Scenario This rule helps you identify idle IAM users to improve account security Solution You can use noncompliant IAM users to log in to Huawei Cloud console or delete these users as needed. For more details, see Logging In as an IAM User and Deleting an IAM User.
IAM user a of account A has created CodeArts project X and wants to invite IAM user b of account B to become a member of project X. The operations in this section will be performed on the CodeArts console and homepage. CodeArts console: Account A authorizes account B.
IAM user a of account A has created CodeArts project X and wants to invite IAM user b of account B to become a member of project X. The operations in this section will be performed on the CodeArts console and homepage. CodeArts console: Account A authorizes account B.
IAM ModelArts uses Identity and Access Management (IAM) for authentication and authorization. For more information about IAM, see Identity and Access Management User Guide.
IAM Functions Permissions Parent Topic: Security
It works with Identity and Access Management (IAM) to provide a variety of authorization methods, including IAM fine-grained authorization, IAM token authorization, namespace authorization, and resource authorization in namespaces.
For more information about IAM, see IAM Service Overview. KooMessage Permissions New IAM users do not come with default permissions, so first add them to one or more groups, then attach policies or roles to these groups.
IAM Functions Permissions Parent topic: Security
Figure 9 Manage User Select the IAM user you want to add to the user group and click OK.
For details about the differences between IAM and enterprise projects, see What Are the Differences Between IAM and Enterprise Management?
IAM user: Select an IAM user and configure an agency for the IAM user. Figure 1 Selecting an IAM user Federated user: Enter the username or user ID of the target federated user. Figure 2 Selecting a federated user Agency: Select an agency name.
Creating a User and Granting Permissions IAM enables you to perform a refined management on your Cloud Eye service. It allows you to: Create IAM users for employees based on your enterprise's organizational structure.
For IAM endpoints, see Regions and Endpoints. Debugging You can debug this API in API Explorer.