Compute
Elastic Cloud Server
Huawei Cloud Flexus
Bare Metal Server
Auto Scaling
Image Management Service
Dedicated Host
FunctionGraph
Cloud Phone Host
Huawei Cloud EulerOS
Networking
Virtual Private Cloud
Elastic IP
Elastic Load Balance
NAT Gateway
Direct Connect
Virtual Private Network
VPC Endpoint
Cloud Connect
Enterprise Router
Enterprise Switch
Global Accelerator
Management & Governance
Cloud Eye
Identity and Access Management
Cloud Trace Service
Resource Formation Service
Tag Management Service
Log Tank Service
Config
OneAccess
Resource Access Manager
Simple Message Notification
Application Performance Management
Application Operations Management
Organizations
Optimization Advisor
IAM Identity Center
Cloud Operations Center
Resource Governance Center
Migration
Server Migration Service
Object Storage Migration Service
Cloud Data Migration
Migration Center
Cloud Ecosystem
KooGallery
Partner Center
User Support
My Account
Billing Center
Cost Center
Resource Center
Enterprise Management
Service Tickets
HUAWEI CLOUD (International) FAQs
ICP Filing
Support Plans
My Credentials
Customer Operation Capabilities
Partner Support Plans
Professional Services
Analytics
MapReduce Service
Data Lake Insight
CloudTable Service
Cloud Search Service
Data Lake Visualization
Data Ingestion Service
GaussDB(DWS)
DataArts Studio
Data Lake Factory
DataArts Lake Formation
IoT
IoT Device Access
Others
Product Pricing Details
System Permissions
Console Quick Start
Common FAQs
Instructions for Associating with a HUAWEI CLOUD Partner
Message Center
Security & Compliance
Security Technologies and Applications
Web Application Firewall
Host Security Service
Cloud Firewall
SecMaster
Anti-DDoS Service
Data Encryption Workshop
Database Security Service
Cloud Bastion Host
Data Security Center
Cloud Certificate Manager
Edge Security
Situation Awareness
Managed Threat Detection
Blockchain
Blockchain Service
Web3 Node Engine Service
Media Services
Media Processing Center
Video On Demand
Live
SparkRTC
MetaStudio
Storage
Object Storage Service
Elastic Volume Service
Cloud Backup and Recovery
Storage Disaster Recovery Service
Scalable File Service Turbo
Scalable File Service
Volume Backup Service
Cloud Server Backup Service
Data Express Service
Dedicated Distributed Storage Service
Containers
Cloud Container Engine
SoftWare Repository for Container
Application Service Mesh
Ubiquitous Cloud Native Service
Cloud Container Instance
Databases
Relational Database Service
Document Database Service
Data Admin Service
Data Replication Service
GeminiDB
GaussDB
Distributed Database Middleware
Database and Application Migration UGO
TaurusDB
Middleware
Distributed Cache Service
API Gateway
Distributed Message Service for Kafka
Distributed Message Service for RabbitMQ
Distributed Message Service for RocketMQ
Cloud Service Engine
Multi-Site High Availability Service
EventGrid
Dedicated Cloud
Dedicated Computing Cluster
Business Applications
Workspace
ROMA Connect
Message & SMS
Domain Name Service
Edge Data Center Management
Meeting
AI
Face Recognition Service
Graph Engine Service
Content Moderation
Image Recognition
Optical Character Recognition
ModelArts
ImageSearch
Conversational Bot Service
Speech Interaction Service
Huawei HiLens
Video Intelligent Analysis Service
Developer Tools
SDK Developer Guide
API Request Signing Guide
Terraform
Koo Command Line Interface
Content Delivery & Edge Computing
Content Delivery Network
Intelligent EdgeFabric
CloudPond
Intelligent EdgeCloud
Solutions
SAP Cloud
High Performance Computing
Developer Services
ServiceStage
CodeArts
CodeArts PerfTest
CodeArts Req
CodeArts Pipeline
CodeArts Build
CodeArts Deploy
CodeArts Artifact
CodeArts TestPlan
CodeArts Check
CodeArts Repo
Cloud Application Engine
MacroVerse aPaaS
KooMessage
KooPhone
KooDrive
Help Center/ Identity and Access Management/ User Guide/ IAM Users/ Viewing or Modifying IAM User Information

Viewing or Modifying IAM User Information

Updated on 2024-12-25 GMT+08:00

As an administrator, you can modify the basic information about an IAM user, change the security settings of the user and the groups which the user belongs to, and view or delete the assigned permissions. To view or modify user information, click Security Settings in the row containing the IAM user.

Figure 1 Going to the IAM user security settings page

To adjust the item columns displayed on the list, click . The Username, Status, and Operation columns are displayed by default. You can also select Description, Last Activity, Created, Access Type, Login Authentication, Virtual MFA Status, Password Age, Access Key (Status, Age, and AK), and External Identity ID.

If you log in to the console or obtain a token more than once in a 5-minute span, the Last Activity column only displays your first login time.

Basic Information

You can view the basic information of each IAM user. The username, user ID, and creation time cannot be modified.

Figure 2 Modifying the status, access type, description, and external identity ID of an IAM user
  • Status: New IAM users are enabled by default. You can set Status to Disabled to disable an IAM user. A disabled user is no longer able to log in to Huawei Cloud through the management console or programmatic access. IAM users can also modify their statuses.
  • Access Type: You can change the access type of the IAM user.
    NOTE:
    • Pay attention to the following when you set the access type of an IAM user:
      • If the user accesses cloud services only by using the management console, select Management console access for Access Type and Password for Credential Type.
      • If the user accesses cloud services only through programmatic calls, select Programmatic access for Access Type and Access key for Credential Type.
      • If the user needs to use a password as the credential for programmatic access to certain APIs, select Programmatic access for Access Type and Password for Credential Type.
      • If the user needs to perform access key verification when using certain services in the console, such as creating a data migration job in the Cloud Data Migration (CDM) console, select Programmatic access and Management console access for Access Type, and select Access Key and Password for Credential Type.
    • If the access type of the user is Programmatic access or both Programmatic access and Management console access, deselecting Programmatic access will restrict the user's access to cloud services. Exercise caution when performing this operation.
  • Description: You can modify the description of the IAM user.
  • External Identity ID: Identifies an enterprise user in federated login using SSO.

User Groups

An IAM user inherits permissions from the groups which the user belongs to. You can change the permissions assigned for an IAM user by changing the groups which the user belongs to. To modify the permissions of a user group, see Viewing or Modifying User Group Information.

Your account belongs to the default group admin, which cannot be changed.

  • Click Add to User Group, and select one or more groups which the user will belong to. The user then inherits permissions of these groups.
    Figure 3 Adding the user to a user group
  • Click Remove on the right of a user group and click OK. The user no longer has the permissions assigned to the group.
    Figure 4 Removing the user from a user group

Security Settings

As an administrator, you can modify the MFA device, login credential, login protection, and access keys of an IAM user on this page. If you are an IAM user and need to change your mobile number, email address, or virtual MFA device, see Security Settings Overview.

Figure 5 IAM user security settings
  • MFA Authentication: You can change the multi-factor authentication (MFA) settings of an IAM user on the Security Settings page.
    • Change or delete the mobile number or email address of the user.
      NOTE:

      The mobile number and email address of the IAM user cannot be the same as those of your account or other IAM users.

    • Remove the virtual MFA device from the user. For more information about MFA authentication and virtual MFA device, see MFA Authentication and Virtual MFA Device.
  • Login Credentials: You can change the login password of the IAM user. For more information, see Changing the Password of an IAM User. You can also delete the login password of the user. This will disable their access to Huawei Cloud. Exercise caution when performing this operation.
  • Login Protection: You can change the login verification method of the IAM user. Three verification methods are available: virtual MFA device, SMS, and email.

    This option is disabled by default. If you enable this option, the user will need to enter a verification code in addition to the username and password when logging in to the console.

  • Access Keys: You can manage access keys of the IAM user. For more information, see Managing Access Keys for an IAM User.

Permissions

You can view or delete permissions of IAM users. To modify permissions of IAM users, see User Groups.

Figure 6 Permissions assigned to an IAM user

To view all authorization records under your account, see Authorization Records.

NOTE:

Deleting the permissions of an IAM user will delete the permissions assigned to the group which the user belongs to. All users in the group will no longer have the permissions. Exercise caution when performing this operation.

Batch Modifying IAM User Information

IAM allows you to batch modify the status, access type, verification method, login password, mobile number, and email address of IAM users. The following describes how to batch modify the status of IAM users. The methods of modifying other information about users are similar to this method.

  1. Log in to the IAM console. In the navigation pane, choose Users.
  2. In the user list, select the users whose information you want to modify, and click Modify above the user list.

    Figure 7 Modifying user information

  3. Select the property you want to modify. In this example, select Status from the drop-down list.

    Figure 8 Selecting the status property

  4. Select the target status to be configured for the selected IAM users.

    Figure 9 Selecting the target status
    NOTE:

    Make sure that this user is no longer in use. Disabling an active user may affect services.

  5. Click OK.
  6. In the displayed dialog box, click OK to confirm the change.

We use cookies to improve our site and your experience. By continuing to browse our site you accept our cookie policy. Find out more

Feedback

Feedback

Feedback

0/500

Selected Content

Submit selected content with the feedback