Authorizing SecMaster
Scenario
SecMaster depends on some other cloud services. To better use SecMaster, you can authorize SecMaster to perform some operations on some cloud services on your behalf. For example, you can allow SecMaster to execute scheduling tasks and manage resources.
Your authorization is required first time you try to use SecMaster. The following table lists the permissions you need to assign to SecMaster.
Permission |
Description |
Assign To |
When to Use |
---|---|---|---|
ECS FullAccess |
All permissions for ECS |
SecMaster_Agency |
|
WAF FullAccess |
Web Application Firewall (WAF) administrator |
SecMaster_Agency |
|
SecMaster FullAccess |
SecMaster administrator |
SecMaster_Agency |
Used to perform operations such as alert handling. |
HSS FullAccess |
Full permissions for HSS |
SecMaster_Agency |
|
EPS ReadOnlyAccess |
Read-only permissions for EPS. |
SecMaster_Agency |
|
Anti-DDoS ReadOnlyAccess |
Read-only permissions for Anti-DDoS. |
SecMaster_Agency |
|
IAM ReadOnlyAccess |
Read-only permissions for IAM. |
SecMaster_Agency |
Used to obtain IAM usernames for executing playbook workflows of batch blocking or unblocking IAM users. |
WAF Administrator |
WAF administrator, who has all permissions for WAF. |
SecMaster_Agency |
|
SMN FullAccess |
All permissions for SMN. |
SecMaster_Agency |
Used to execute playbook workflows related to notifications, for example, the "Automatic Notification of High-Risk Alerts" workflow. |
RDS ReadOnlyAccess |
Read-only permissions for RDS |
SecMaster_Agency |
|
EIP ReadOnlyAccess |
Read-only permissions for EIP |
SecMaster_Agency |
|
Tenant Guest |
Read-only permissions for all cloud services except IAM |
SecMaster_Agency |
Used to query resource information of cloud services except IAM in the baseline check scenario. |
NAT ReadOnlyAccess |
Read-only permissions for NAT Gateway. |
SecMaster_Agency |
Used to obtain asset information in NAT Gateway for asset information synchronization in the asset management scenario. |
VPC FullAccess |
All permissions for VPC. |
SecMaster_Agency |
|
OBS OperateAccess |
Allows a user to perform the basic operations, such as viewing the bucket list, obtaining bucket metadata, listing objects in a bucket, querying bucket location, uploading objects, obtaining objects, deleting objects, and obtaining an object ACL. |
SecMaster_Agency |
Used to query, upload, and download objects when the OBS plug-in is used. |
ELB ReadOnlyAccess |
Read-only permissions for ELB. |
SecMaster_Agency |
|
CFW FullAccess |
All permissions for CFW. |
SecMaster_Agency |
|
Prerequisites
- The IAM account has been authorized. For details, see How Do I Grant Permissions to an IAM User?
- You have purchased SecMaster.
Authorizing SecMaster
- Log in to the management console.
- Click
in the upper left corner of the management console and select a region or project.
- Click
in the upper left corner of the page and choose Security & Compliance > SecMaster.
- In the navigation pane on the left, choose Workspaces > Management.
Figure 1 Workspaces > Management
- (Optional) In the upper part of the workspace management page, click Entrusted Service Authorization - Current Tenant.
The service authorization page is automatically displayed the first time you log in.
- On the page for assigning permissions, select all required permissions (which are selected by default), select Agree to authorize, and click Confirm.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.