Help Center/ Application Service Mesh/ Best Practices/ Reducing the Agency Permissions of ASM Users
Updated on 2024-09-24 GMT+08:00

Reducing the Agency Permissions of ASM Users

Background

ASM permission management is implemented through IAM agencies. However, users authorized prior to July 2024 may have excessive agency permissions. For security purposes, you are advised to reduce the agency permissions.

Procedure

  1. Log in to the IAM console.
  2. In the navigation pane, choose Agencies. Then, search for asm_admin_trust and click its name.
  3. Click the Permissions tab and delete all permissions.
  4. Click Authorize, search for and select the CCE Administrator policy, and click Next. Set Scope to Region-specific projects, select the region where the ASM service is to be used, and click OK.
  5. Click Authorize, search for and select the Tenant Guest policy, and click Next. Set Scope to Region-specific projects, select the region where the ASM service is to be used, and click OK.

Grant permissions that deleted in 3 again. Otherwise, an exception may occur.