How Do I Limit Agency Permissions for Cross-Region Image Replication?
Scenarios
During cross-region image replication, an agency is required to verify cloud service permissions in the destination region. So, you need to create a cloud service agency before the replication. In the past, you might be required to assign the Tenant Administrator or IMS Administrator system-defined role to an agency, but the two roles provide more excessive permissions than the agency actually needs.
You can use fine-grained system-defined policies to limit the agency permissions.
Procedure
- Log in to the console.
- Hover the mouse pointer over the username in the upper right corner and select Identity and Access Management from the drop-down list.
- In the navigation pane, choose Agencies.
- Click the name of the agency you used for cross-region replication.
- On the Permissions tab page, if the Tenant Administrator or IMS Administrator role is displayed, proceed with the following steps to limit the agency permissions.
- Click Authorize. Select system-defined policies based on the image type. For details, see Table 1.
- Click Next and set the minimum authorization scope.
- Click OK.
- Click Finish to return back to the permission list.
- In the list, select the Tenant Administrator and IMS Administrator roles and click Delete.