Multi-Account Management
With DSC multi-account management, you can consolidate multiple cloud accounts under a single master account, centrally managing their data assets. This helps enterprises streamline security tasks, including automated sensitive data discovery, classification, and threat monitoring.
Currently, DSC multi-account management is not supported for federated users.
This topic describes how to implement multi-account management.
- Enabling multi-account management: Once this feature is enabled, the security administrator can centrally manage data security for all member accounts from the security operations account, eliminating the need to log in to each account individually. This section provides the enablement process.
- Adding a member account: A delegated administrator can add organizational member accounts to DSC. Then, the delegated administrator can access and manage the cloud asset data of that member account in DSC.
- Removing a member account: If you no longer want the delegated administrator to manage a member account's assets, you can remove it from the management scope.
Concepts
The following table provides the main concepts in DSC multi-account management.
| Concept | Description |
|---|---|
| Management account | A management account controls organizational member accounts and can enable cloud services as trusted services within the organization. |
| Delegated administrator | A delegated administrator account is a member account that has special permissions in an organization. The management account of your organization can designate a member account to be a delegated administrator account for a trusted service. All the users under the delegated administrator account will have organizational management capabilities for trusted services (for example, DSC). |
| Member account | A delegated administrator can add organizational member accounts to DSC. Then, the delegated administrator can access and manage the cloud asset data of that member account in DSC. |
Multi-Account Management Process
In the following example, we use account A to manage the assets of account B.
| Operation | Description |
|---|---|
| 1. Enable the Organizations service. | For details, see Enabling the Organizations Service. |
| 2. Authorize DSC as a trusted service. | For details, see Enabling a Trusted Service. |
| 3. Add account A as a delegated administrator. | If account A is a management account, skip this step. If account A is not a management account, the management account should add account A as a delegated administrator. For details, see Specifying a Delegated Administrator. NOTICE: The management account can grant or revoke delegated administrator permissions for member accounts. Organizational changes may take 1 to 2 minutes to update. Refresh the page to check updates. |
| 4. Invite account B to join the organization. | Only a management account or delegated administrator account can perform multi-account management operations. Invite an account to join the organization and grant permissions.
|
| 5. Add account B to the DSC organization members. | Log in to the DSC console using account A. On the Multi-account Management page, add account B to the DSC organization. Then, you can manage and view the assets of account B under account A. NOTICE: To add an account to the DSC organization, ensure the account has not subscribed to DSC. If a subscription exists, cancel it before attempting to add the account. |
Example of Multi-Account Asset Management
The following sections describe how to build a multi-account management system. Delegated administrators can manage the data security of assets across Huawei Cloud accounts in DSC.
Scenario: Huawei Cloud accounts A, B, C, D, and E belong to the same organization. Huawei Cloud account A is the management account of the organization. Huawei Cloud accounts B, C, D, and E are the members of the organization. Huawei Cloud account A sets Huawei Cloud account B as the delegated administrator of DSC. Huawei Cloud account B can centrally manage the assets of Huawei Cloud accounts B, C, D, and E with the asset management, sensitive data identification, baseline check, data audit, and data masking provided by DSC.

Notes and Constraints
- Once a member account joins the DSC organization, the administrator or delegated administrator can view and manage its cloud assets. However, LTS assets do not support multi-account management. To view or manage the LTS assets belonging to a member account, the administrator or delegated administrator need to use the Current account drop-down list to switch directly to that member account.
- If the delegated administrator permissions for the trusted DSC are revoked from an account, multi-account management will be disabled for that account. Additionally, any member account resources previously added by that account will be automatically removed in 2 minutes.
- Once a member account is removed from the organization, DSC will automatically remove its resources from the administrator's view in 2 minutes.
- Only the accounts displayed on the Multi-account Management page can be managed.
- An account that has enabled DSC cannot be added as a member account of DSC. A member account that has been added to DSC cannot enable DSC or use DSC independently.
Enabling Account Management
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - In the navigation pane on the left, choose Multi-account Management.
- Click Enable multi-account management.
Adding a Member Account
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - In the navigation pane on the left, choose Multi-account Management.
- Click Batch Add. In the displayed dialog box, select members that have been added to the organization.
- Click OK to add the member accounts to DSC.
Removing a Member Account
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - In the navigation pane on the left, choose Multi-account Management.
- In the Operation column a member account, click Remove. In the displayed dialog box, click OK.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot