Help Center/ Edge Security/ User Guide/ Permissions Management/ Creating a User Group and Granting Permissions
Updated on 2024-01-26 GMT+08:00

Creating a User Group and Granting Permissions

This section describes how to use IAM to implement fine-grained permissions control for your EdgeSec resources. With IAM, you can:

  • Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials, providing access to EdgeSec resources.
  • Grant only the permissions required for users to perform a specific task.
  • Entrust a Huawei account or a cloud service to perform efficient O&M on your EdgeSec resources.

If your Huawei account does not require individual IAM users, skip this section.

This section describes the procedure for granting permissions. Figure 1 shows the procedure.

Prerequisites

Before granting permissions to a user group, you need to learn about the permissions supported by EdgeSec in Table 1 and choose policies or roles based on your requirements.

Table 1 EdgeSec system roles

System Role/Policy Name

Description

Type

Dependency

EdgeSec FullAccess

All permissions of EdgeSec

System policy

None

EdgeSec ReadOnlyAccess

Read-only permission of EdgeSec

System policy

Permission Granting Process

Figure 1 Process for granting permissions
  1. Create a user group and assign permissions.

    Create a user group on the IAM console and assign the EdgeSec FullAccess permissions to the group.

  2. Create a user and add it to a user group.

    Create a user on the IAM console and add the user to the group created in 1.

  3. Log in and verify permissions.

    Log in to the EdgeSec console by using the created user, and verify that the user only has permissions of EdgeSec.

    Choose any other service from Service List. If a message appears indicating that you do not have permissions to access the service, the EdgeSec FullAccess policy has already taken effect.