Help Center/ IAM Identity Center/ User Guide/ Permissions Management/ Creating a User and Granting IAM Identity Center Permissions
Updated on 2025-02-20 GMT+08:00

Creating a User and Granting IAM Identity Center Permissions

You can use Identity and Access Management (IAM) for fine-grained permissions control for your IAM Identity Center. With IAM, you can:

  • Create IAM users for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing IAM Identity Center resources.
  • Grant only the permissions required for users to perform a specific task.
  • Entrust an account or a cloud service to perform efficient O&M on your IAM Identity Center resources.

If your account does not require individual IAM users, you may skip over this section.

This section describes the procedure for granting permissions (see Figure 1).

Prerequisites

Before granting permissions to user groups, learn about system-defined permissions in permissions for IAM Identity Center. To grant permissions for other services, learn about all system-defined permissions.

Process Flow

Figure 1 Process of granting IAM Identity Center permissions

  1. On the IAM console, create a user group and grant it permissions (IdentityCenter ReadOnlyAccess as an example).

  2. Create an IAM user and add it to the created user group.
  3. Log in as the created IAM user and verify the IdentityCenter ReadOnlyAccess permissions.