Help Center> Anti-DDoS Service> User Guide> Advanced Anti-DDoS User Guide> Permissions Management> Creating a User and Granting the AAD Access Permission
Updated on 2023-03-02 GMT+08:00

Creating a User and Granting the AAD Access Permission

You can use Identity and Access Management (IAM) to implement refined permission control for AAD resources. To be specific, you can:

  • Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials, providing access to AAD resources.
  • Grant only the permissions required for users to perform a task.
  • Entrust a Huawei Cloud account or cloud service to perform professional and efficient O&M to your AAD resources.

If your Huawei Cloud account does not require individual IAM users, skip this section.

This section describes the procedure for granting permissions (see Figure 1).

Prerequisites

Learn about the permissions supported by AAD and choose policies or roles according to your requirements.

Process

Figure 1 Process for granting permissions
  1. Create a user group and assign permissions to it.

    Create a user group on the IAM console, and assign the AAD FullAccess permission to the group.

  2. Create an IAM user.

    Create a user on the IAM console and add the user to the group created in 1.

  3. Log in and verify the user's permissions.

    Log in to the management console as the created user, and verify the user's permissions.

    Click and select any other services (for example, the policy contains only the AAD FullAccess permission). If a message indicating that the permission is insufficient is displayed, the AAD FullAccess permission takes effect.