Creating a User and Granting Permissions
Use IAM to implement fine-grained permissions control over your DeHs. With IAM, you can:
- Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing DeH resources.
- Grant only the permissions required for users to perform a specific task.
- Use IAM to entrust an account or cloud service to perform efficient O&M on your DeH resources.
If your account does not require individual IAM users, skip over this section.
This section describes the procedure for granting permissions (see Figure 1).
Prerequisites
Learn about the permissions (see Permission Management) supported by DeH and choose policies or roles according to your requirements.
Authorization Process
- Create a user group and assign permissions.
Create a user group on the IAM console and assign the DeHReadOnlyAccess permission to the group.
- Create a user and add the user to the user group.
Create a user on the IAM console and add the user to the group created in 1.
- Log in as the IAM user and verify permissions.
Log in to the management console using the created user, and verify that the user only has read permissions for DeH.
- Click Service List and find Dedicated Host. On the displayed page, click Buy DeH in the upper right corner. If you cannot buy a DeH (after the DeH ReadOnlyAccess permission is assigned), it indicates that the DeH ReadOnlyAccess permission has already taken effect.
- Choose any other service in the Service List (assume that there is only the ECS Viewer policy). If a message appears indicating that you have insufficient permissions to access the service, the DeH ReadOnlyAccess policy has already taken effect.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot