Esta página ainda não está disponível no idioma selecionado. Estamos trabalhando para adicionar mais opções de idiomas. Agradecemos sua compreensão.
- Service Overview
- User Guide
-
FAQs
-
Product Consulting
- What Does SA Do?
- Why Is There No Attack Data or Only A Small Amount of Attack Data?
- What Is the Data Source of Situation Awareness?
- How Do I Get Information About the Most Vulnerable Assets?
- What Are the Dependencies and Differences Between SA and Other Security Services?
- What Are the Differences Between SA and HSS?
- Why Cannot the Total ECS Quota Be Less Than the Number of Existing ECSs?
- Can SA Be Used Across Accounts?
- How Do I Update My Security Score?
- How Do I Handle a Brute-force Attack?
- How Do I Assign Operation Permissions to an Account?
- How Do I Handle the 403 forbidden Error Reported by SA?
- Why Is the Event Data in SA Inconsistent with That in WAF and HSS?
- What Are Differences Between SA and SecMaster?
- Purchase Consulting
- Regions and AZs
-
Product Consulting
- General Reference
Copied.
How Do I Assign Operation Permissions to an Account?
To use functions in Baseline Inspection, Resource Manager, and Logs modules, your account must have the Tenant Administrator permission and IAM-related permissions.
This topic describes how to configure permissions to use a specific SA function.
- Configuring Permissions to Use Baseline Inspection
- Configuring Permissions to Use Resource Manager and Logs
Prerequisites
You have obtained the administrator account and its password.
Configuring Permissions to Use Baseline Inspection
To use Baseline Inspection, you need to configure permissions and policies as described in the following steps. Do not select other permissions or policies, or this function may still be unavailable after the configuration.
- Log in to the management console.
- Click
in the upper left corner of the page and choose Management & Governance > Identity and Access Management.
- Add IAM-related permissions.
- In the navigation pane on the left, choose Permissions > Policies/Roles. In the upper right corner of the displayed page, click Create Custom Policy.
- Configure a policy.
- Policy Name: Enter a policy name.
- Scope: Select Global services.
- Policy View: Select JSON.
- Policy Content: Copy the following content and paste it in the text box.
{ "Version": "1.1", "Statement": [ { "Effect": "Allow", "Action": [ "iam:users:getUser", "iam:securitypolicies:getLoginPolicy", "iam:credentials:listCredentials", "iam:users:getUserLoginProtect", "iam:agencies:listAgencies", "iam:securitypolicies:getProtectPolicy", "iam:users:listUsers", "iam:securitypolicies:getPasswordPolicy", "iam:groups:listGroups", "iam:permissions:listRolesForAgencyOnProject", "iam:users:listUsersForGroup", "iam:projects:listProjectsForUser", "iam:permissions:listRolesForAgencyOnDomain" ] } ] }
- Click OK.
- In the navigation pane one the left, choose Agencies.
- In the agency list, select ssa_admin_trust to go to the details page.
- Click the Permissions Assigned tab and click Assign.
- In the permission configuration area, search for and select Tenant Administrator and the permission created in 3.
Figure 1 Baseline inspection permissions - Example
- Click Next in the lower part of the page and set the minimum authorization scope.
- Click OK.
Configuring Permissions to Use Resource Manager and Logs
To use Baseline Inspection, you need to configure permissions and policies as described in the following steps. Do not select other permissions or policies, or this function may still be unavailable after the configuration.
- Log in to the management console.
- Click
in the upper left corner of the page and choose Management & Governance > Identity and Access Management.
- In the navigation pane one the left, choose Agencies.
- In the agency list, select ssa_admin_trust to go to the details page.
- Click the Permissions Assigned tab and click Assign.
- In the permission configuration area, search for and select Tenant Administrator.
Figure 2 Resource Manager permissions
- Click Next in the lower part of the page and set the minimum authorization scope.
- Click OK.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot