Cross-Account Access Delegation and Resource Management
Company A and company B have created account A and account B, respectively. If account A wants to authorize account B to manage its resources, account A can create an agency in IAM to establish a trust relationship between the two accounts.
Requirements
- Account A has purchased different types of resources on Huawei Cloud. Account A wants to authorize account B to manage its VPC resources in the CN-Hong Kong region.
- Account B can authorize one or more employees (IAM users) of company B to manage account A's resources.
- Account A can modify or cancel the authorization provided to account B at any time.
Solution
- Account A creates an agency on the IAM console to authorize account B to manage its resources.
- Account B assigns permissions to its IAM users to manage account A's resources specified in the agency.
- Account A can modify or delete the agency at any time. Deleting the agency will automatically cancel the permissions assigned to account B and its IAM users for managing account A's resources.
Delegating an Account to Manage Resources
Account A performs the following procedure to delegate account B to manage its VPC resources in the CN-Hong Kong region.
- Log in to Huawei Cloud using account A. On the IAM console, choose Agencies in the navigation pane.
- Click Create Agency, and enter an agency name, for example, VPC Resources O&M.
- Select the Account agency type, and enter the delegated account name, for example, B-Company.
- Set Validity Period to Unlimited.
Figure 2 Creating an agency
- Click Done.
- In the displayed dialog box, click Authorize.
- Select VPC FullAccess and click Next.
- Specify the authorization scope as Region-specific projects, and select CN-Hong Kong.
- Click OK.
The agency is displayed in the agency list.
Account A can modify the permissions or validity period of the agency or delete the agency based on service requirements.
Managing Resources of an Account
After the agency is created, account B can switch roles to account A to manage account A's resources. To do this, account B needs to have obtained account A's account name and the agency name.
- Log in to the Huawei Cloud management console using account B.
- Click the username in the upper right corner, and choose Switch Role.
Figure 3 Switching roles
- Enter the account name of the delegating party. The agency created by the delegating party is displayed automatically.
Figure 4 Switching roles
- Click OK to switch to account A.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot