Updated on 2024-11-15 GMT+08:00

Overview of an Account

Accounts in Your Organization

An account is used to contain your Huawei Cloud resources. It is the smallest unit of an organization. Each organization has one management account and multiple member accounts.

Table 1 Account types

Account Type

Function

Quota

Management account

With the Organizations service, you can use the management account to create an organization and manage OUs, accounts, and policies for the organization.

1 (Each organization can have exactly one management account.)

Member account

Except for the management account, other accounts in an organization are member accounts. Each member account is part of only one organization at a time. Generally, member accounts hold resources for a specific application or project of an organization.

9

Impacts of Being in an Organization

When you invite an existing account to your organization or create a new account in your organization, Organizations will automatically make the following changes to the new member account:

  • A service-linked agency is created in the member account. It is a cloud service agency with the system-defined permission OrganizationsServiceLinkedAgencyPolicy for all resources.
  • The permissions of the new member account are affected by service control policies and tag policies. You may have service control policies and tag policies attached to the root OU or the OU that contains the new member account. If so, the policies will apply to the new member account and all IAM users in the member account.
  • When you use the management account to enable a trusted service, the trusted service can create a service-linked agency for that trusted service in the member account.

Helpful links:

  • Inviting an Account to Join Your Organization: You can create invitations, manage invitations you have sent, and accept or reject invitations.
  • Creating an Account: You can use the management account to create new accounts.
  • Closing an Account: You can use the management account to close any unwanted accounts that you have created. Invited accounts cannot be closed.
  • Moving an Account: You can move accounts from one OU to another OU.
  • Viewing Account Details: You can view the account name, account ID, the time when it joined an organization, any account-owing OUs, and the policies, tags, and delegated services that are attached to the account.
  • Removing a Member Account from Your Organization: You can use the management account to remove member accounts from your organization.
  • Viewing Account Details: When you sign in to the management account of your organization, on the Accounts page, you can view account details, including the account list, invitations, and creation requests. You can also invite, create, close, move, remove, and cancel any pending invitations.