Help Center/ My Account/ User Guide/ Permissions/ Using IAM to Grant Access to My Account/ Using IAM Roles or Policies to Grant Access to My Account
Updated on 2025-11-24 GMT+08:00

Using IAM Roles or Policies to Grant Access to My Account

System-defined permissions in Role/Policy-based Authorization provided by Identity and Access Management (IAM) let you control access to My Account. With IAM, you can:

  • Create IAM users or user groups for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing My Account.
  • Grant users only the permissions required to perform a given task based on their job responsibilities.
  • Entrust a Huawei Cloud account to perform efficient O&M on My Account.

If your Huawei Cloud account meets your permissions requirements, you can skip this section.

Figure 1 shows the process flow of role/policy-based authorization.

Prerequisites

Before granting permissions to user groups, learn about system-defined permissions in Role/Policy-based Authorization. To grant permissions for other services, learn about all system-defined permissions supported by IAM.

Process Flow

Figure 1 Process of granting My Account permissions using role/policy-based authorization

  1. On the IAM console, create a user group and grant it permissions (BSS Administrator as an example).
  2. Create an IAM user and add it to the created user group.
  3. Log in as the IAM user and verify permissions.

    Log in to the Huawei Cloud My Account as the created IAM user and check whether the user has the permissions needed to modify account information.

    If the modification is successful, the BSS Administrator permissions are granted to the user.