Updated on 2023-03-07 GMT+08:00

Assigning Permissions to an IAM User

IAM users created without being added to any groups do not have permissions. The administrator can assign permissions to these IAM users on the IAM console. After authorization, the users can use cloud resources in your account as specified by their permissions.

Procedure

  1. In the user list, click Authorize in the row that contains the target user.
  2. On the Authorize User page, select an authorization mode and permissions.

    • Inherit permissions from user groups: Add the IAM user to certain groups to inherit their permissions.

      If you select this option, select the user groups to which the user will belong.

    • Select permissions: Directly assign specific permissions to the IAM user.

      If you select this option, select permissions, click Next in the lower right, and then go to 3.

    • If you add an IAM user to the default group admin, the user becomes an administrator and can perform all operations on all cloud services.
    • If you add a user to multiple user groups, the user inherits the permissions that are assigned to these groups.
    • For details on the system permissions of all cloud services supported by IAM, see "System Permissions".
    • If you have enabled enterprise management, you cannot create projects in IAM.

  3. On the Select Scope page, select enterprise projects that the IAM user can access. You do not need to perform this step if you have selected Inherit permissions from user groups.
  4. Click OK.

    You can go to the Permissions > Authorization page and view or modify the permissions of the IAM user.

Users access cloud services in the RU-Moscow-OP4 region as virtual users authorized through federated authentication. They are not real users who exist on SberCloud, and need to be authorized in HUAWEI CLOUD's default regions and the RU-Moscow-OP4 region, respectively. For details, see How Do I Grant Cloud Service Permissions in the ME-Abu Dhabi-OP5 Region to IAM Users?