Updated on 2025-07-31 GMT+08:00

Adding a LakeFormation Role to a User

After a LakeFormation role is created, you can add an IAM user or an agency user to the role. Users associated with this role will inherit its permissions.

These operations can be performed only on the Users or Role page of the console.

Prerequisites

You have created a LakeFormation role. For details, see Creating a LakeFormation Role and Granting Permissions.

Binding a Role to a User

  1. Log in to the LakeFormation console.
  2. Select the target LakeFormation instance from the drop-down list box on the left and choose Data Permissions > Users.
  3. Locate a user and click Add in the Operation column. In the displayed dialog box, select the role to be added, and click OK.

    After the role is authorized, the user bound with the role inherits its permissions.

    You can also bind users or user groups in the MRS cluster with the role on the Ranger web UI after LakeFormation is interconnected with the MRS cluster.

Binding a User to a Role

  1. Log in to the LakeFormation console.
  2. Select the target LakeFormation instance from the drop-down list box on the left and choose Data Permissions > Roles.
  3. Click Create, set Role Name and Description, and click OK.
  4. Locate the create role and click Add IAM User or Add Agency in the Operation column. In the displayed dialog box, select the target user and click OK.

    After the role is authorized, the user bound with the role inherits its permissions.

Reference