Help Center/ Identity and Access Management/ User Guide/ IAM User Management/ Modifying Security Settings for an IAM User
Updated on 2026-09-23 GMT+08:00

Modifying Security Settings for an IAM User

As an administrator, you can modify the password, MFA device, login protection, and access keys of an IAM user.

Constraints

  • If the password of an IAM user is automatically generated, it cannot be changed on the Security Settings tab of the IAM console. To change the password, go to the Basic Information page of My Account.
  • IAM users can change their passwords on the Basic Information tab. If you want to change the password of your account, see How Do I Change My Password?
  • By default, only the IAM user's MFA device can be changed on the Security Settings tab. The MFA device of the account cannot be changed.
  • The mobile number and email address of the IAM user cannot be the same as those of the account or other IAM users.

Changing the Password of an IAM User

As an administrator, you can reset the password of an IAM user if the user has forgotten the password and no email address or mobile number has been bound to the user. You can also delete the login password of the user. This will disable their access to Huawei Cloud. Exercise caution when performing this operation.

  1. Log in to the IAM console as the administrator.
  2. In the user list, click a username or click Security Settings in the Operation column to access the user details page.

    Figure 1 Changing the password of an IAM user

  3. Click the Security Settings tab. In the Login Credentials area, click in the Login Password row to reset the login password for the IAM user.

    Figure 2 Changing a password
    Table 1 Parameters for resetting a user login password

    Reset Password Method

    Description

    Set by user

    The user sets the password after logging in to the console through a one-time link sent by email.

    Automatically generated

    The system automatically generates a random password. After the user is created, the new password can be downloaded and sent to the user.

    Set now

    The administrator sets a custom password for the user and sends the new password to the user.

Changing the MFA Device for an IAM User

You can only change the MFA device for an IAM user, but not for the account.

  1. Log in to the IAM console as the administrator.
  2. In the user list, click a username or click Security Settings in the Operation column to access the user details page.
  3. Click the Security Settings tab and change the MFA device of the IAM user.

    • Change or delete the mobile number or email address of the user.

      The mobile number and email address of the IAM user cannot be the same as those of the account or other IAM users.

    • Reset the MFA device for a user. For more information about MFA and virtual MFA device, see MFA Authentication.
    • Bind a USB key to an IAM user or unbind the USB key from the user.
    Figure 3 Changing the MFA device

Modifying the Login Protection Configuration for an IAM User

Login protection is disabled by default. If you enable this option, the user will need to enter a verification code in addition to the username and password when logging in to the console.

  1. Log in to the IAM console as the administrator.
  2. In the user list, click a username or click Security Settings in the Operation column to access the user details page.
  3. Click the Security Settings tab and modify the login protection configuration of the IAM user. This option is disabled by default. You can choose from the following methods for secondary verification:

    • SMS
    • Email address
    • Virtual MFA device

  4. Enable or disable (default) API login protection as needed when you select Virtual MFA device. API login protection asks you for both a password and a virtual MFA device to obtain an IAM user token. Without API login protection, you can obtain the token with only a password. To obtain an IAM user token, see Obtaining a User Token Through Password and Virtual MFA.

Related Operations