Files
doc-exports/docs/dataartsstudio/umn/dataartsstudio_03_0051.html
chenxiaoxiong f9e2808b7c DataArts UMN 20250810 version
Reviewed-by: Pruthi, Vineet <vineet.pruthi@t-systems.com>
Co-authored-by: chenxiaoxiong <chenxiaoxiong@huawei.com>
Co-committed-by: chenxiaoxiong <chenxiaoxiong@huawei.com>
2025-09-02 10:44:13 +00:00

26 lines
5.2 KiB
HTML

<a name="dataartsstudio_03_0051"></a><a name="dataartsstudio_03_0051"></a>
<h1 class="topictitle1">What Should I Do If the Agency List Fails to Be Obtained During Agency Configuration?</h1>
<div id="body1596770627841"><div class="section" id="dataartsstudio_03_0051__section078023115318"><h4 class="sectiontitle">Possible Causes</h4><p id="dataartsstudio_03_0051__p9345183715313">If error message "Policy doesn't allow iam:agencies:listAgencies to be performed." is displayed when you are creating a workspace-level or job-level agency, you may lack the required permissions.</p>
</div>
<div class="section" id="dataartsstudio_03_0051__section16384115718319"><h4 class="sectiontitle">Solution</h4><p id="dataartsstudio_03_0051__p114111905412">Add the <strong id="dataartsstudio_03_0051__b9107064596">View Agency List</strong> policy for the current user.</p>
<p id="dataartsstudio_03_0051__p6950202217419">You can create a custom policy (query the agency list based on specified conditions) and assign it to a user group for refined access control.</p>
<ol id="dataartsstudio_03_0051__ol1954153411420"><li id="dataartsstudio_03_0051__li854203411416"><span>Log in to the management console.</span></li><li id="dataartsstudio_03_0051__li1754113415416"><span>On the management console, hover the mouse pointer over the username in the upper right corner, and choose <strong id="dataartsstudio_03_0051__b17172123981311">Identity and Access Management</strong> from the drop-down list.</span></li><li id="dataartsstudio_03_0051__li115419341849"><span>In the navigation pane, choose <strong id="dataartsstudio_03_0051__b129449785814">Permissions</strong> &gt; <strong id="dataartsstudio_03_0051__b1153620468595">Roles</strong>. Then, click <strong id="dataartsstudio_03_0051__b11945872580">Create Custom Policy</strong>.</span></li><li id="dataartsstudio_03_0051__li125523415415"><span>Enter a policy name.</span><p><div class="fignone" id="dataartsstudio_03_0051__fig1745613124210"><span class="figcap"><b>Figure 1 </b>Policy name</span><br><span><img id="dataartsstudio_03_0051__image8558341548" src="en-us_image_0000002269195661.png" title="Click to enlarge" class="imgResize"></span></div>
</p></li><li id="dataartsstudio_03_0051__li5551134241"><span>Set <span class="parmname" id="dataartsstudio_03_0051__parmname175515341744"><b>Scope</b></span> based on the region where the service is deployed. In this example, you need to grant IAM the permission to query the agency list based on specified conditions. As IAM is a global service, select <strong id="dataartsstudio_03_0051__b1262544515167">Global services</strong> for <strong id="dataartsstudio_03_0051__b177165471615">Scope</strong>.</span></li><li id="dataartsstudio_03_0051__li125513341143"><span>Select <strong id="dataartsstudio_03_0051__b567393171719">Visual editor</strong> for <strong id="dataartsstudio_03_0051__b8673538175">Policy View</strong>.</span></li><li id="dataartsstudio_03_0051__li1655163417413"><a name="dataartsstudio_03_0051__li1655163417413"></a><a name="li1655163417413"></a><span>Configure a policy in <span class="parmname" id="dataartsstudio_03_0051__parmname957063192415"><b>Policy Content</b></span>.</span><p><ol type="a" id="dataartsstudio_03_0051__ol18552341144"><li id="dataartsstudio_03_0051__li455163419416">Select <span class="parmname" id="dataartsstudio_03_0051__parmname18111520115316"><b>Allow</b></span>.</li><li id="dataartsstudio_03_0051__li955534241">Select <span class="parmname" id="dataartsstudio_03_0051__parmname248221075515"><b>Identity and Access Management (IAM)</b></span> for <strong id="dataartsstudio_03_0051__b16392231558">Select service</strong>.</li><li id="dataartsstudio_03_0051__li45663416418">Select <strong id="dataartsstudio_03_0051__b852664971419">iam:agencies:listAgencies</strong> for <strong id="dataartsstudio_03_0051__b77819380556">Select action</strong>.</li></ol>
</p></li><li id="dataartsstudio_03_0051__li9562341746"><span>Click <strong id="dataartsstudio_03_0051__b84604122175">OK</strong>.</span></li><li id="dataartsstudio_03_0051__li456534645"><span>Add the policy defined in <a href="#dataartsstudio_03_0051__li1655163417413">7</a> to the group to which the current user belongs. For details, see "Creating a User Group and Granting Permissions" in the <em id="dataartsstudio_03_0051__i1010052751716">Identity and Access Management User Guide</em>.</span></li><li id="dataartsstudio_03_0051__li3561341842"><span>In the navigation pane on the left, choose <strong id="dataartsstudio_03_0051__b7616174817175">Agencies</strong>. Locate the target agency, click <strong id="dataartsstudio_03_0051__b361613489179">Authorize</strong> in the <strong id="dataartsstudio_03_0051__b136166484177">Operation</strong> column, add the created custom policy to the agency, and click <strong id="dataartsstudio_03_0051__b661615483176">OK</strong>.</span><p><p id="dataartsstudio_03_0051__p19561341941">The current user can log out of the system and then log in again to obtain the agency list.</p>
</p></li></ol>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="dataartsstudio_03_0035.html">DataArts Factory</a></div>
</div>
</div>
<script language="JavaScript">
<!--
initImageViewer('.imgResize');
var msg_imageMax = "view original image";
var msg_imageClose = "close";
//--></script>