Help Center/ Object Storage Migration Service/ User Guide/ Permissions Management/ Creating a User and Assigning OMS Permissions
Updated on 2024-12-19 GMT+08:00

Creating a User and Assigning OMS Permissions

This chapter describes how to use IAM for fine-grained permissions control for your OMS resources. With IAM, you can:

  • Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing OMS resources.
  • Assign only the minimum permissions required for users to perform a given task.
  • Entrust a Huawei Cloud account or cloud service to perform professional and efficient O&M on your OMS resources.

If your Huawei Cloud account does not need individual IAM users, skip over this chapter.

Figure 1 shows the procedure for granting permissions.

Prerequisites

Before assigning permissions to user groups, you should learn about system policies supported by OMS and select the policies based on service requirements. For more information about system policies supported by OMS, see OMS Permissions. For the system policies of other services, see System-defined Permissions.

Process Flow

Figure 1 Process of granting OMS permissions
  1. Create a user group and assign permissions to it.
  2. Create a user and add the user to the user group..

    Create a user on the IAM console and add the user to the group created in 1.

    You must select both Programmatic access and Management console access for Access Type when creating an IAM user.

  3. Sign in to the console as the created user.

    In the authorized region, perform the following operations:

    • Choose Service List > Object Storage Migration Service. On the OMS console, click Create Migration Task in the upper right corner. If a migration task can be created, the OMS Administrator permission has already taken effect.
    • Choose any service other than OMS in Service List. If a message appears indicating that you have insufficient permissions to access the service, the OMS Administrator permission has already taken effect.