Updated on 2022-02-22 GMT+08:00

IAM Operations That Can Be Recorded by CTS

Table 1 lists Identity and Access Management (IAM) operations that can be recorded by Cloud Trace Service (CTS).

Table 1 IAM operations that can be recorded by CTS

Operation

Resource Type

Trace Name

Obtaining a token

token

createTokenByPwd

Obtaining a token

token

createTokenByHwAccessKey

Obtaining a token

token

createTokenByToken

Obtaining a token

token

createTokenByAssumeRole

Login

user

login

Login failure

user

loginFailed

Logout

user

logout

Changing the password

user

changePassword

Creating a user

user

createUser

Modifying user information

user

updateUser

Deleting a user

user

deleteUser

Changing the password

user

updateUserPwd

Creating an access key (AK/SK)

user

addCredential

Deleting an access key (AK/SK)

user

deleteCredential

Changing the email address

user

modifyUserEmail

Changing the mobile number

user

modifyUserMobile

Changing the password

user

modifyUserPassword

Uploading a profile picture

user

modifyUserPicture

Changing the password of a user (by the administrator)

user

setPasswordByAdmin

Creating a user group

userGroup

createUserGroup

Updating a user group

userGroup

updateUserGroup

Deleting a user group

userGroup

deleteUserGroup

Adding a user to a user group

userGroup

addUserToGroup

Removing a user from a user group

userGroup

removeUserFromGroup

Creating a project

project

createProject

Modifying project information

project

updateProject

Changing project status

project

updateProjectStatus

Creating an agency

agency

createAgency

Modifying an agency

agency

updateAgency

Deleting an agency

agency

deleteAgency

Switching the role

user

switchRole

Registering an identity provider

identityProvider

createIdentityProvider

Updating an identity provider

identityProvider

updateIdentityProvider

Deleting an identity provider

identityProvider

deleteIdentityProvider

Registering a mapping

mapping

createMapping

Updating a mapping

mapping

updateMapping

Deleting a mapping

mapping

deleteMapping

Registering a protocol

protocol

createProtocol

Updating a protocol

protocol

updateProtocol

Deleting a protocol

protocol

deleteProtocol

Granting permissions to a user group under a domain

roleGroupDomain

assignRoleToGroupOnDomain

Canceling permissions of a user group under a domain

roleGroupDomain

unassignRoleToGroupOnDomain

Granting permissions to a user group for a project

roleGroupProject

assignRoleToGroupOnProject

Delete permissions of a user group for a project

roleGroupProject

unassignRoleToGroupOnProject

Updating the login authentication policy

domain

updateSecurityPolicies

Updating the password policy

domain

updatePasswordPolicies

Updating the ACL

domain

updateACLPolicies

Unbinding a virtual MFA device

MFA

UnBindMFA