- Service Overview
- Billing
- Getting Started
-
User Guide
- Before You Start
- Buying an Instance
- Instance Management
-
Enterprise Administrator Guide
- Logging In to the OneAccess Administrator Portal
- User Management
-
Resources
- Overview
-
Applications
- Adding an Application
- Enabling, Disabling, or Deleting an Application
- General Information
- Authentication Integration
- Synchronization Integration
- Login Configuration
- Access Control
- Object Models
- Authorization Management
- API Permission Management
- Application Permission Management
- Security Settings
- Audit Logs
- APIs
- Authentication
- Security
- Audit
- Settings
- Common User Guide
- Key Operations Recorded by CTS
-
Best Practices
- OneAccess Best Practices
- Identity Source Integration
-
Application Integration
-
Logging In to the Huawei Cloud Through User Portal
- Introduction
- Logging In to Single Huawei Cloud Account via OneAccess Without Password (SAML - Virtual User SSO)
- Logging In to Multiple Huawei Cloud Accounts via OneAccess Without Password (SAML - Virtual User SSO)
- Logging In to Single Huawei Cloud Account via OneAccess Without Password (SAML - IAM User SSO)
- Logging In to Multiple Huawei Cloud Accounts via OneAccess Without Password (SAML - IAM User SSO)
- Logging In to Huawei Cloud via OneAccess Without Password (OIDC)
- SSO Access to Applications Through SAML
- SSO Access to Applications Through OAuth 2.0
- SSO Access to Applications Through OIDC
- SSO Access to Applications Through CAS
- SSO Access to Applications Through Plug-in Autocompletion
-
Logging In to the Huawei Cloud Through User Portal
- Data Synchronization
- Authentication Provider Integration
- Authorizing IAM Users to Access a OneAccess Instance Administrator Portal
- API Usage
- Configuring MFA for User Login
- Developer Guide
-
API Reference
- Before You Start
- API Overview
-
OneAccess APIs
-
Management APIs
- Calling APIs
- Access Credentials
-
User Management
- Creating a User
- Modifying a User
- Deleting a User
- Enabling a User
- Disabling a User
- Changing a User Password
- Verifying and Modifying the Original User Password
- Querying User Details by User ID
- Querying User Details by Username
- Querying the User List
- Authorizing an Application Account
- Querying All Authorized Application Accounts of a User
- Organization Management
- Application Organization Management
- Application Account Management
- Application Role Management
- User APIs
- Application Integration APIs
-
Management APIs
- Appendix
- FAQs
- General Reference
Copied.
Managing Authorization
With authorization management, administrators can authorize application accounts to applications and users within their scope of permissions. Users can be authorized in batches by organization, and application roles and permissions can be assigned to authorized users, in addition, you can edit, delete, enable, or disable authorized application accounts. (This function must be granted by the super administrator.)
Authorizing an Application Account
Manage the mappings between OneAccess users and application accounts. You can map a OneAccess user to accounts of different applications.
- Log in to the administrator portal.
- On the top navigation bar, choose Users > Authorization.
- On the displayed page, click User Authorization under the application to be authorized.
NOTE:
The Authorization Management page displays only the applications accessible to the administrator.
- Click Add User in the upper right corner. On the Add Account page, click the name of the organization to which the user to be authorized belongs and select it.
NOTE:
On the User Authorization page, only the application accounts on which the common administrator has permissions are displayed.
- Click Save to complete the authorization.
Editing an Application Account
The administrator can edit the application account on the user authorization page and modify its information.
- Log in to the administrator portal.
- On the top navigation bar, choose Users > Authorization.
- On the page for authorization management, click User Authorization under an application.
- Click Modify in the Operation column of the user to modify user authorization information.
- Enter the new information and click Save.
Disabling or Enabling an Application Account
- Log in to the administrator portal.
- On the top navigation bar, choose Users > Authorization.
- On the page for authorization management, click User Authorization under an application.
- Click
in the Status column of the user to be disabled. After an account is disabled, the application is not displayed on the user portal of the user and it cannot be accessed. You can click
to enable the account. After the account is enabled, the application is displayed on the user portal of the user and the application can be accessed.
Deleting an Application Account
- Log in to the administrator portal.
- On the top navigation bar, choose Users > Authorization.
- On the page for authorization management, click User Authorization under an application.
- Click Delete in the Operation column of the user to be deleted.
- In the dialog box that is displayed, click OK to cancel the user's permission to access the application.
Adding an Application Role or Permission
The prerequisite for granting application roles/permissions is to configure application permissions. For details, see Application Permission Management.
On the User Authorization page, the application accounts that the common administrator has permissions are displayed. The common administrator can add roles and permissions to these application accounts. For applications configured with role-based application permission management, you can only add roles. For applications configured with role-, permission-, and resource-based application permission management, you can add roles and permissions.
- Log in to the administrator portal.
- On the top navigation bar, choose Users > Authorization.
- On the page for authorization management, click User Authorization under an application.
- Click Application Roles/Permissions in the Operation column of the user to be operated.
- Grant permissions by application role or permission.
- The application permission of the application is set to role-based application permission management.
In the displayed dialog box, select a role name and click OK.
- The application permission of an application is set to role-, permission-, and resource-based application permission management.
- In the Application Roles/Permissions dialog box, select Authorize by role, select a role name, and click OK.
- In the Application Roles/Permissions dialog box, select Authorize by permission and click Add Permission. In the Add Permission dialog box, select a permission type, select resources, and click OK.
- In the Application Roles/Permissions dialog box, select Authorize by role, select a role name, and click OK.
- The application permission of the application is set to role-based application permission management.
Searching for an Application Account
On the User Authorization page, the administrator can filter application accounts based on the search criteria.
- Log in to the administrator portal.
- On the top navigation bar, choose Users > Authorization.
- On the page for authorization management, click User Authorization under an application.
- On the User Authorization page, you can filter users.
- You can select the start time and end time based on the application account creation time, and click OK to filter the application accounts created in the specified time range.
- You can select Account and enter an account name or name in the text box to filter application accounts that meet the search criteria.
- You can select User and enter an account name or name in the text box to filter application accounts that meet the search criteria.
- You can select an organization and enter the organization name or code in the text box to filter the application accounts.
- You can select Enable or Disable from the State drop-down list box to filter application accounts.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot