检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Rule Logic If an IAM user is in the disabled state, this user is compliant. If an IAM user is not allowed to access the management console, this user is compliant. If an enabled IAM user who is allowed to access the management console has MFA enabled, this user is compliant.
Users Querying the MFA Device Information of an IAM User Listing Login Protection Configurations of IAM Users Querying the Login Protection Configuration of an IAM User Modifying the Login Protection Configuration of an IAM User Binding a Virtual MFA Device Unbinding a Virtual MFA
this rule is noncompliant. 3.3 iam-user-group-membership-check iam If an IAM user is not in any of the specified IAM user groups, this user is noncompliant. 3.3 iam-user-last-login-check iam If an IAM user does not log in to the system within the specified time range, this user
If you use an IAM user to manage users, the IAM user must have the Security Administrator permission. (New IAM users do not have any permissions by default and cannot obtain the user list). Log in to the IAM console using your Huawei Cloud account or HUAWEI ID.
Using CloudTable Through an IAM Account This chapter describes Identity and Access Management (IAM) fine-grained permissions management for your CloudTable. With IAM, you can: Create IAM users for employees based on your enterprise's organizational structure.
Log in to the IAM console using a Huawei Cloud account or an IAM account, locate the IAM user that the target instance belongs to, and add it to the user group created in 2. The IAM user will inherit permissions of the user group.
"iam:agencies:list*", "iam:agencies:createAgency", "iam:agencies:createServiceLinkedAgencyV5", "coc:agency:get", "coc:agency:create", "iam:permissions:grantRoleToAgency",
"iam:agencies:list*", "iam:agencies:createAgency", "iam:agencies:createServiceLinkedAgencyV5", "coc:agency:get", "coc:agency:create", "iam:permissions:grantRoleToAgency",
IAM users with IAM ReadOnlyAccess, CCE FullAccess, or CCE ReadOnlyAccess assigned can directly access the data in Overview.
IAM user: Select an IAM user and configure an agency for the IAM user. Figure 1 Selecting an IAM user Federated user: Enter the username or user ID of the target federated user. Figure 2 Selecting a federated user Agency: Select an agency name.
Figure 1 My Credentials On the API Credentials page, view the account name, account ID, IAM user name, IAM user ID, project name, and project ID. The project ID varies depending on the region where your service is located.
Figure 1 My Credentials On the API Credentials page, view the account name, account ID, IAM user name, IAM user ID, project name, and project ID. The project ID varies depending on the region where your service is located.
Figure 1 My Credentials On the API Credentials page, view the account name, account ID, IAM user name, IAM user ID, project name, and project ID. The project ID varies depending on the region where your service is located.
Figure 1 My Credentials On the API Credentials page, view the account name, account ID, IAM user name, IAM user ID, project name, and project ID. The project ID varies depending on the region where your service is located.
IAM user: Select an IAM user and configure an agency for the IAM user. Figure 1 Selecting an IAM user Federated user: Enter the username or user ID of the target federated user. Figure 2 Entering a federated user Agency: Select an agency name.
Each IAM user can create a maximum of two access keys. The quota cannot be increased.
Use an IAM user. Specifically, use a Huawei account to log in to the Huawei Cloud console, create an IAM user, and grant the IAM user necessary permissions.
Rule Logic If an IAM user is the root user, this user is compliant. If an IAM user is disabled, this user is compliant. If a non-root IAM user in the enabled state was added to the admin user group, this user is noncompliant.
(Optional) Creating an IAM User If you have registered on Huawei Cloud, you can create an IAM user on the IAM console. For details, see Creating an IAM User.
If the password of an IAM user does not meet the password strength requirements, this IAM user is noncompliant. iam-user-last-login-check iam If an IAM user does not log in to the system within the specified time range, the result is non-compliant. iam-user-mfa-enabled iam If multi-factor