forked from docs/doc-exports
Reviewed-by: Hajba, László Antal <laszlo-antal.hajba@t-systems.com> Co-authored-by: fanqinying <fanqinying@huawei.com> Co-committed-by: fanqinying <fanqinying@huawei.com>
24 lines
4.9 KiB
HTML
24 lines
4.9 KiB
HTML
<a name="dc_03_0901"></a><a name="dc_03_0901"></a>
|
|
|
|
<h1 class="topictitle1">Creating a User and Granting Permissions</h1>
|
|
<div id="body8662426"><p id="dc_03_0901__en-us_topic_0000001082024069_p3525192874519">Use <a href="https://docs.otc.t-systems.com/usermanual/iam/iam_01_0026.html" target="_blank" rel="noopener noreferrer">IAM</a> for fine-grained permissions control over your resources. With IAM, you can:</p>
|
|
<ul id="dc_03_0901__en-us_topic_0000001082024069_ul10181544819"><li id="dc_03_0901__en-us_topic_0000001082024069_li15349173754610">Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials, providing access to cloud resources.</li><li id="dc_03_0901__en-us_topic_0000001082024069_li17350173715460">Grant only the permissions required for users to perform a specific task.</li><li id="dc_03_0901__en-us_topic_0000001082024069_li1618754482">Entrust another account or cloud service to perform professional and efficient O&M on your cloud resources.</li></ul>
|
|
<p id="dc_03_0901__en-us_topic_0000001082024069_p8413121644716">Skip this part if your account does not require individual IAM users.</p>
|
|
<p id="dc_03_0901__en-us_topic_0000001082024069_p13407105754713">The following is the procedure for granting permissions.</p>
|
|
<div class="section" id="dc_03_0901__en-us_topic_0000001082024069_section149731733152219"><h4 class="sectiontitle">Prerequisites</h4><p id="dc_03_0901__en-us_topic_0000001082024069_p107331754719">Before assigning permissions to user groups, you should learn about Direct Connect system policies and select the policies based on service requirements. For details about system-defined permissions of Direct Connect, see <a href="dc_01_0008.html">Permissions</a>. For system-defined permissions of other cloud services, see <a href="https://docs.otc.t-systems.com/permissions/index.html" target="_blank" rel="noopener noreferrer">Permissions</a>.</p>
|
|
</div>
|
|
<div class="section" id="dc_03_0901__en-us_topic_0000001082024069_section197617372174"><h4 class="sectiontitle">Process Flow</h4><div class="fignone" id="dc_03_0901__en-us_topic_0000001082024069_fig1447123814172"><span class="figcap"><b>Figure 1 </b>Process for granting Direct Connect permissions</span><br><span><img id="dc_03_0901__en-us_topic_0000001082024069_image1244723814172" src="en-us_image_0000001562084113.jpg"></span></div>
|
|
<ol id="dc_03_0901__en-us_topic_0000001082024069_ol15447153801718"><li id="dc_03_0901__li1140112579375"><a name="dc_03_0901__li1140112579375"></a><a name="li1140112579375"></a><a href="https://docs.otc.t-systems.com/usermanual/iam/iam_01_0030.html" target="_blank" rel="noopener noreferrer">Create a user group and assign permissions</a>.<p id="dc_03_0901__p34014574372">Create a user group on the IAM console and assign the <strong id="dc_03_0901__b107904661411">DCAAS ReadOnlyAccess</strong> policy to the group.</p>
|
|
</li><li id="dc_03_0901__li361517462916"><a href="https://docs.otc.t-systems.com/usermanual/iam/iam_01_0031.html" target="_blank" rel="noopener noreferrer">Create a user and add the user to the user group</a><p id="dc_03_0901__en-us_topic_0000001082024069_p94477384175">Create a user on the IAM console and add the user to the group created in <a href="#dc_03_0901__li1140112579375">1</a>.</p>
|
|
</li><li id="dc_03_0901__en-us_topic_0000001082024069_li1444753881716"><a href="https://docs.otc.t-systems.com/usermanual/iam/iam_01_0032.html" target="_blank" rel="noopener noreferrer">Log in to the management console as the created user</a>.<p id="dc_03_0901__en-us_topic_0000001082024069_p471616471318">Switch to the authorized region and verify the permissions.</p>
|
|
<ul id="dc_03_0901__en-us_topic_0000001082024069_ul271842718415"><li id="dc_03_0901__en-us_topic_0000001082024069_li36639366570">Choose <strong id="dc_03_0901__b144617591633">Service List</strong> > <strong id="dc_03_0901__b1521919216414">Network</strong> > <strong id="dc_03_0901__b63836512410">Direct Connect</strong>. On the <strong id="dc_03_0901__b52814151942">Connections</strong> page, select a connection and click <strong id="dc_03_0901__b187382219418">Modify</strong> in the <strong id="dc_03_0901__b15409202512414">Operation</strong> column to modify the connection. If the connection cannot be modified, <strong id="dc_03_0901__b888314420410">DCAAS ReadOnlyAccess</strong> has taken effect.</li><li id="dc_03_0901__en-us_topic_0000001082024069_li146631936105719">Choose any other service in <strong id="dc_03_0901__en-us_topic_0000001082024069_b2876192222514">Service List</strong>. If a message appears indicating that you have insufficient permissions to access the service, the <strong id="dc_03_0901__en-us_topic_0000001082024069_b207951944172512">DCAAS ReadOnlyAccess</strong> policy has already taken effect.</li></ul>
|
|
</li></ol>
|
|
</div>
|
|
</div>
|
|
<div>
|
|
<div class="familylinks">
|
|
<div class="parentlink"><strong>Parent topic:</strong> <a href="dc_03_0900.html">Permissions Management</a></div>
|
|
</div>
|
|
</div>
|
|
|