Help Center/ Identity and Access Management/ User Guide/ IAM User Management/ Modifying the User Group Which an IAM User Belongs to
Updated on 2025-07-03 GMT+08:00

Modifying the User Group Which an IAM User Belongs to

An IAM user inherits permissions from the user groups that the user belongs to. You can change the permissions assigned to an IAM user by changing the user groups that the user belongs to.

Constraints

Your account belongs to the default group admin, which cannot be changed.

Procedure

  1. Log in to the IAM console as the administrator.
  2. Click a username to go to the user details page.
  3. Click Add to User Group on the User Groups tab.

    Figure 1 Adding a user to a user group

  4. In the Add to User Group dialog box, select the target user groups which you want to add the user to.

    A user can be added to one or more user groups.

    Figure 2 Configuring group membership

  5. Click OK. The selected user groups will be displayed in the user group list.

    After a user is added to a user group, the user inherits all the permissions of it.

  6. To remove an IAM user from a user group, locate the target group and click Remove in the Operation column. In the displayed dialog box, click OK. After the user is removed from a group, the permissions inherited from the group will be revoked.

    Figure 3 Removing a user from a user group

Related Operations

To modify the permissions of a user group, see Managing Permissions of a User Group.