Updated on 2024-04-08 GMT+08:00

Delegating Resource Access to Another Account

The agency function enables you to delegate another account to implement O&M on your resources based on assigned permissions.

You can delegate resource access only to accounts. The accounts can then delegate access to IAM users under them.

  1. (Optional) Account B assigns permissions to an IAM user to manage specific resources for account A.

    1. Create a user group, and grant it permissions required to manage account A's resources.
    2. Create a user and add the user to the user group.

  2. Account B or the authorized user manages account A's resources.

    1. Log in to account B's account and switch the role to account A.
    2. Switch to region A and manage account A's resources in this region.