Managing Account Groups
Scenarios
You can add multiple managed resource accounts to a resource account group and then authorize and authenticate accounts by group.
An account group is associated with a department and does not belong to an individual. If you have management permissions for the Account Group module, you can view information about all account groups in your department and its lower-level departments. However, you cannot view information about account groups of your superior department.
Notes and Constraints
- If you are the administrator of a department, you can add a resource account in your department to an account group in a lower-level department.
- If you have management permissions for the Account Group module, you can view accounts in your department and the superior department. However, for the accounts in the superior department, only the account list is visible to you. Account details are restricted.
- If you have management permissions for the Account Group module, you can remove a resource account in a superior department out of the current account group, but you have no permissions to add the removed account back.
- A resource account can be added to multiple account groups.
- When you create an account group, it automatically belongs to your department by default. For details about how to modify a department, see Viewing or Modifying Basic Information and Members of a Resource Account Group.
Prerequisites
Your role has the management permission for the Account Group module. For details about how to check the permissions of each role, see Role.
Creating a Resource Account Group
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Account Group to go to the account group list page.
- Click New. In the displayed dialog box, configure the account group information.
Table 1 Parameters for creating an account group Parameter
Description
Account Group
Enter a custom name for the group. This name must be unique in your bastion host system.
The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.
Remarks
(Optional) Enter a brief description of the account group. A maximum of 128 characters can be entered.
- Click OK.
Return to the account group list page. You can view the new account group. You also need to add resource accounts to the account group. For details, see Adding a Member to or Removing a Member from an Account Group.
Adding a Member to or Removing a Member from an Account Group
You can add resource accounts in the bastion host system to an account group for centralized management and batch operations.
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Account Group to go to the account group list page.
- Add or remove members based on your needs.
- Adding a member
- In the Operation column of the target account group, click Add Account.
- In the displayed dialog box, select the resource account to be added to the group and click OK.
You can search for the target resource account by resource account, associated resource, host address, or application address.
- Removing a member
- Click Remove Account in the Operation column of the target resource group.
- In the displayed dialog box, select the resource account to be removed from the group and click OK.
You can search for the target resource account by resource account, associated resource, host address, or application address.
- Adding a member
Viewing or Modifying Basic Information and Members of a Resource Account Group
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Account Group to go to the account group list page.
- Click the name of the target account group or click Manage in the Operation column of the target account group to go to the details page.
- View or modify the basic information about the account group.
- In the Basic Info area, view the name, department, and description of the account group.
- In the Basic Info area, click Edit on the right to modify the name, department, and description of the account group.
- View or modify the members of the account group.
- In the Group Members area, view the list of resource accounts in the current account group.
- In the Group Members area, click Add on the right to add resource accounts to the resource group.
- In the resource account list below the Group Members area, click Remove to remove a resource account from the current group.
Batch Verifying the Status of Resource Accounts in an Account Group
You can verify the connection status of managed resource accounts in an account group in just a few clicks.
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Account Group to go to the account group list page.
- Select the account group to be verified and click Test and verify below the list. The configuration window is displayed.
- In the configuration window, configure verification parameters.
Table 2 Parameters for verifying a resource account Parameter
Description
Connect Timeout
Configure a timeout for connecting to the target host. The default value is 10 seconds.
Done notification
Configure the way to receive the task notification. You can select multiple channels. By default, no channel is selected.
- Email: After a task is complete, a notification is sent to the specified recipients by email. To send email notifications, ensure that you have configured an email server. For details, see Configuring a Server to Send Emails.
- SMS: After a task is complete, a notification is sent to the specified recipients by SMS. To send SMS notifications, ensure that you have configured an SMS gateway. For details, see Configuring an SMS Gateway to Send Messages. Make sure SMS Gateway under Third-party is selected for SMS Conf during configuration.
- Click OK.
- Click Go to the task center to view the verification result.
- Click the title of the account group verification task. On the displayed task details page, view the verification result in the Result column. Figure 1 Verification result
Deleting a Resource Account Group
Deleting a resource account group will remove all its member accounts from the group. This action does not affect the original configurations of the resource accounts in the group.
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Account Group to go to the account group list page.
- Delete any account groups that you no longer need.
- Deleting a single account group
- Click Delete in the Operation column of the target account group.
- In the displayed dialog box, click OK.
- Batch deleting account groups
- In the account group list, select all the target account groups.
- Click Delete in the lower left corner.
- In the displayed dialog box, click OK.
- Deleting a single account group
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot