RCP Principles
RCP Types
RCPs are classified as either system-defined policies or custom policies, depending on who creates them.
- System-defined policies
Huawei Cloud has preset a system-defined policy named RCPFullAccess for organizations. The organization administrator can directly use the system-defined policy when attaching RCPs to OUs or accounts. Such policies cannot be modified. For details about available system-defined RCPs, see System-defined RCPs.
- Custom policies
If system-defined policies cannot meet your requirements, you can use the management account to create and modify custom RCPs based on the actions supported by each service. Custom policies extend and supplement system-defined policies. You can create custom policies for Organizations in a policy editor or JSON view.
RCP Effects on Permissions
- Permissions boundaries
RCPs do not actually grant any permissions to an entity. They only set permissions boundaries for the entity. When RCPs are attached to an OU or a member account, they do not directly grant permissions to that OU or member account. Instead, the RCPs only determine what permissions are available for that member account or member accounts under that OU. The granted permissions can be applied only if they are allowed by the RCPs. Users cannot perform any actions that are denied by RCPs even if the actions are granted to the users by IAM policies.
Suppose that an RCP is attached to a member account. The RCP allows action A but denies action B. The member account then can grant its IAM users the permission to perform action A but not action B. Even if the permission to perform action B is assigned, the permission cannot be applied.
- Layer-by-layer permissions check
To allow a member account to perform an action on a cloud service, the action must be explicitly allowed at each level from the organization's root to each OU in the account's direct path, including the target account.
Figure 1 Organizational structure example with Allow statements added to the root, OU, and account y
To deny a specific account the permission to perform an action, any RCP can deny the permission from the organization's root to each OU in the account's direct path, including the target account.
Figure 2 Organizational structure with Deny statements added to an OU and the impact on account y
- Allow by default
When RCPs are enabled for an organization, the RCPFullAccess policy is attached by default to all OUs and accounts unless you attach explicit deny policies to the OUs or accounts.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot