Creating a User and Assigning OMS Permissions
This chapter describes how to use IAM for fine-grained permissions control for your OMS resources. With IAM, you can:
- Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing OMS resources.
- Assign only the minimum permissions required for users to perform a given task.
- Entrust a Huawei Cloud account or cloud service to perform professional and efficient O&M on OMS.
If your Huawei Cloud account does not need individual IAM users, then you may skip over this chapter.
Figure 1 shows the procedure for granting permissions.
Prerequisites
Learn about the permissions (see Permission Management) supported by OMS and choose policies or roles according to your requirements. For the system policies of other services, see System Permissions.
Process Flow
- Create a user group and assign permissions to it.
- If the IAM users who will be added to this group need all OMS permissions, attach the system-defined policies supported by SMS, including OMS Administrator and OBS Administrator, to the group.
- If the IAM users only need specific OMS permissions, create custom policies and attach these policies to the user group. For details, see How Do I Obtain Required Permissions for the Source and Destination Platform Accounts?
- Create an IAM user.
Create a user on the IAM console and add the user to the group created in 1.
You must select both Programmatic access and Management console access for Access Type when creating an IAM user.
- Log in and verify permissions.
Log in to the OMS console as the created user, and verify the user's permissions.
- Choose Service List > Object Storage Migration Service. On the OMS console, click Create Migration Task in the upper right corner. If a migration task can be created, the OMS Administrator permission has already taken effect.
- Choose any other service in Service List. If a message appears indicating that you have insufficient permissions to access the service, the OMS Administrator permission has already taken effect.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot