Creating a User and Granting the AAD Access Permission
You can use Identity and Access Management (IAM) to implement refined permission control for AAD resources. To be specific, you can:
- Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials, providing access to AAD resources.
- Grant only the permissions required for users to perform a task.
- Entrust a Huawei Cloud account or cloud service to perform professional and efficient O&M to your AAD resources.
If your Huawei Cloud account does not require individual IAM users, skip this section.
This section describes the procedure for granting permissions (see Figure 1).
Prerequisites
Learn about the permissions supported by AAD and choose policies or roles according to your requirements.
Process
- Create a user group and assign permissions to it.
Create a user group on the IAM console, and assign the AAD FullAccess permission to the group.
- Create an IAM user.
Create a user on the IAM console and add the user to the group created in 1.
- Log in and verify the user's permissions.
Log in to the management console as the created user, and verify the user's permissions.
Click and select any other services (for example, the policy contains only the AAD FullAccess permission). If a message indicating that the permission is insufficient is displayed, the AAD FullAccess permission takes effect.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot