Help Center/ Organizations/ FAQs/ What Are the Differences in Access Control Between IAM and Organizations?
Updated on 2026-07-24 GMT+08:00
What Are the Differences in Access Control Between IAM and Organizations?
- They control different entities. IAM policies define permissions for IAM users, user groups, and agencies within an account. SCPs specify the maximum available permissions for IAM identities in a member account. RCPs specify the maximum available permissions for resources in an organization. NCPs specify the maximum available permissions for VPC endpoints in an organization.
- Their permission scopes are distinct but interdependent. Even if IAM policies grant certain actions to a user, those actions are blocked if denied by an SCP, RCP, or NCP. Granted permissions take effect only if they are also permitted by the applicable SCPs, RCPs, and NCPs.
- SCPs, RCPs, and NCPs restrict permissions but do not grant them. They define the upper boundary of available permissions for IAM identities and resources in an organization. To grant permissions, use IAM policies for IAM users, user groups, and agencies.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
The system is busy. Please try again later.
For any further questions, feel free to contact us through the chatbot.
Chatbot