Help Center/ Object Storage Service/ User Guide/ Permissions Control/ Configuring IAM Permissions/ Creating an IAM User and Granting OBS Permissions
Updated on 2025-08-26 GMT+08:00

Creating an IAM User and Granting OBS Permissions

You can use IAM for fine-grained access control over your OBS resources. With IAM, you can:

  • Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing OBS resources.
  • Manage permissions on a principle of least permissions (PoLP) basis.
  • Entrust a Huawei Cloud account or cloud service to perform efficient O&M on your OBS resources.

If your Huawei Cloud account does not require individual IAM users, skip this chapter.

Figure 1 shows the procedure for granting permissions.

Prerequisites

You have learned about the OBS permissions that can be assigned to a user group.

Process

Figure 1 Process of granting an IAM user the OBS permissions

The example here describes how to grant an IAM user the Tenant Guest permission for OBS.

  1. Create a user group and assign permissions.

    Create a user group on the IAM console, and assign the Tenant Guest permission to it.

  2. Create an IAM user and add it to the user group.

    Create a user on the IAM console and add it to the user group created in 1.

  3. Log in to the console and verify permissions.

    Log in to the OBS Console as the created user and verify the assigned permission.

    • If you can view the bucket list of the account and can click any bucket to obtain its basic information, but you cannot create or delete buckets or perform any other operations, the Tenant Guest permission is in effect.
    • Go to an OBS bucket. If you can view the object list and can download objects, but you cannot upload or delete objects or perform any other operations, the Tenant Guest permission is in effect.