Help Center/ IoT Device Access/ User Guide/ Permissions Management/ Creating a User and Granting IoTDA Permissions
Updated on 2024-12-11 GMT+08:00

Creating a User and Granting IoTDA Permissions

You can use Identity and Access Management (IAM) for fine-grained permissions control for your IoTDA resources. With IAM, you can:

  • Create IAM users for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing IoTDA resources.
  • Grant users only the permissions required to perform a given task based on their job responsibilities.
  • Entrust a Huawei Cloud account or a cloud service to perform efficient O&M on your IoTDA resources.

If your Huawei Cloud account does not need individual IAM users, then you may skip this section.

This section describes the procedure for granting permissions. Figure 1 shows the process flow.

Prerequisites

Before granting permissions to user groups, learn about system-defined permissions supported by IoTDA. To grant permissions for other services, learn about all system-defined permissions supported by IAM.

Process Flow

Figure 1 Process of granting IoTDA permissions
  1. Create a user group and grant it permissions: Create a user group on the IAM console and assign the IoTDA ReadOnlyAccess permissions to the group.
  2. Create a user and add it to the user group: Create a user on the IAM console and add the user to the user group created in 1.
  3. Log in as the IAM user and verify permissions: In the authorized region, perform the following operations:
    • Choose Service List > IoT Device Access. Then register a device on the IoTDA console. If a message appears indicating that you have insufficient permissions to perform the operation, the IoTDA ReadOnlyAccess policy is in effect.
    • Choose another service from Service List. If a message appears indicating that you have insufficient permissions to access the service, the IoTDA ReadOnlyAccess policy is in effect.