Updated on 2026-09-17 GMT+08:00

Using IAM Identity Policies to Grant Access to SMS

System-defined permissions in identity policy-based authorization provided by IAM let you control access to SMS. With IAM, you can:

  • Create IAM users or user groups for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing SMS resources.
  • Grant users only the permissions required to perform a given task based on their job responsibilities.
  • Entrust a Huawei Cloud account or a cloud service to perform efficient O&M on your SMS resources.

If your Huawei Cloud account meets your permissions requirements, you can skip this section.

Figure 1 shows the process flow of identity policy-based authorization.

Prerequisites

Before granting permissions, learn about Identity Policy-based Authorization for SMS. To grant permissions for other services, learn about all system-defined permissions supported by IAM.

Process Flow

Figure 1 Process for granting SMS permissions
  1. On the IAM console, create an IAM user or create a user group.
  2. Attach a system-defined policy (SMSReadOnlyPolicy as an example) to the user or user group.
  3. Log in as the IAM user and verify permissions.

    In the authorized region, perform the following operations:

    • Choose Service List > Server Migration Service. On the SMS console, locate the server to be migrated and click Configure in the Target column. If a message appears indicating insufficient permissions to perform the operation, the SMSReadOnlyPolicy policy is in effect.
    • Choose any other service in the Service List. If a message appears indicating insufficient permissions to access the service, the SMSReadOnlyPolicy policy is in effect.

Example Custom Policies

You can create custom identity policies to supplement the system-defined identity policies of SMS.

To create a custom identity policy, choose either visual editor or JSON.

  • Visual editor: Select cloud services, actions, resources, and request conditions. This does not require knowledge of policy syntax.
  • JSON: Create a JSON policy or edit an existing one.

For details, see Creating a Custom Identity Policy and Attaching It to a Principal.

When creating a custom Identity policy, use the Resource element to specify the resources the policy applies to and use the Condition element (service-specific condition keys) to control when the policy is in effect. The following is an example of custom identity policies for SMS.

  • Example 1: Grant permissions to query server details.
    {
        "Version": "5.0",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "sms:server:get"
                ]
            }
        ]
    }
  • Example 2: Grant permissions to list, query, and delete migration tasks.
    {
        "Version": "5.0",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "sms:server:deleteTask",
                    "sms:server:getTask",
                    "sms:server:listTask"
                ]
            }
        ]
    }