Help Center> Identity and Access Management> User Guide (Paris Regions) > Getting Started> Creating a User and Adding the User to a User Group
Updated on 2024-04-08 GMT+08:00

Creating a User and Adding the User to a User Group

As a security administrator, you can create a user and add the user to a user group. The user automatically inherits the permissions of the user group.

Only Cloud Alliance users with the administrator rights can create and manage users in IAM. Other users must use Cloud Customer Space to create users. On the Rights page, click Add user. For details, see Adding a user. More help about the Cloud Customer Space can be found on Flexible Engine assistance.

Procedure

  1. Choose Management & Deployment > Identity and Access Management.
  2. In the navigation pane, choose Users. Then click Create User.
  3. On the Create User page, enter a username.
  4. Specify the credential type.

    Credential Type

    Scenario

    API password

    • Used to log in to the management console.
    • Used together with development tools (such as APIs, CLI, and SDK) that support password authentication to access cloud services.

    Access key

    Used together with development tools (such as APIs, CLI, and SDK) that support key authentication to access cloud services.

  5. Select a user group from the drop-down list in the User Groups area.

    • You can enter a keyword to quickly find the target user group.
    • You can add a user to multiple user groups.
    Perform the subsequent operation based on the credential type you select in 4.

    Credential Type

    Follow-up Operation

    API password

    Go to 6.

    Access key

    Click OK. The user is created, and an access key is automatically generated for the user.

    NOTE:

    Access keys are credentials used for identity authentication in IAM. You can download access keys only when they are generated.

  6. Click Next. Then specify API Password Type.

    API Password Type

    Description

    Follow-up Operation

    Set by user

    The system will send a one-time login URL to the user. The user can set a password by clicking on the one-time login URL sent over email.

    1. Enter an email address for receiving the login link.
    2. (Optional) Enter a mobile number.

    Automatically generated

    The system will generate a random 10-character password after you click OK. The user can use development tools (such as APIs, CLI, and SDK) that support password authentication to access cloud services.

    1. (Optional) Enter an email address.
    2. (Optional) Enter a mobile number.

    Set now

    Set a password now.

    1. (Optional) Enter an email address.
    2. (Optional) Enter a mobile number.
    3. Set a password and enter it again.
    NOTE:
    The password must meet the following requirements:
    • Must contain 6 to 32 characters.
    • Complies with the password policy.
    • Must contain at least two types of the following: uppercase letters, lowercase letters, digits, and special characters (~`!?,.:;-_'"(){}[]/<>@#$%^&*+|\= and spaces).
    • Cannot be the username or the username spelled backwards. For example, if the username is A12345, the password cannot be A12345, a12345, 54321A, or 54321a.

  7. Select API Password Reset to require the user to change the password at first login. This option is enabled by default. Keep it enabled for security purposes.
  8. Click OK.

    The user is created successfully.