检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
You can configure identity conversion rules on the IAM console to achieve the following: Display enterprise users with different names in Huawei Cloud. Assign permissions to enterprise users to use Huawei Cloud resources by mapping these users to IAM user groups.
Deleting User Groups Procedure To delete a user group, do the following: Log in to the IAM console. In the navigation pane, choose User Groups. In the user group list, click Delete in the row that contains the user group to be deleted.
Category Item Quota Adjustable User IAM users 50 Yes Characters allowed in a username 32 No Groups to which a user can be added 10 No AK/SK pairs that a user can create 2 No Virtual MFA devices that can be associated with a user 1 No Permissions (including system-defined permissions
For IAM endpoints, see Regions and Endpoints. Debugging You can debug this API in API Explorer.
If you do not a password for logging in to the management console, request the administrator to create an access key for you on the IAM console. For details, see Managing Access Keys for an IAM User. Parent topic: Passwords and Credentials
", "name": "IAMAgency", "agency_urn": "iam::d78cbac186b744899480f25b...8:agency:IAMAgency", "trust_domain_id": "a2cd82a33fb043dc9304bf72...
Log in to the IAM console. On the IAM console, choose Agencies from the navigation pane on the left, and click Create Agency on the displayed page. Enter an agency name.
For details about how to obtain the account ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. group_id Yes String User group ID.
For details about how to obtain a user group ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. project_id Yes String Project ID.
For details about how to obtain the agency ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. project_id Yes String Project ID of the delegating party.
For details about how to obtain the agency ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. domain_id Yes String ID of the delegating account.
For details about how to obtain the agency ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. project_id Yes String Project ID of the delegating party.
For IAM endpoints, see Regions and Endpoints. Debugging You can debug this API in API Explorer.
For IAM endpoints, see Regions and Endpoints. Debugging You can debug this API in API Explorer.
This condition must be used together with g:MFAPresent. g:ProjectName String Project name. g:UserId String IAM user ID. g:UserName String IAM username. (Optional) Switch to the JSON view and modify the policy content in JSON format.
You need to map the federated users to IAM user groups. In this way, the federated users can obtain the permissions of the user groups to use Huawei Cloud resources. Ensure that user groups have been created.
Procedure Use the DomainA account to create an IAM user (for example, UserB) and add the user to GroupC by following the instructions in Adding Users to a User Group. Ensure that the IAM user can programmatically access Huawei Cloud services.
For details about how to obtain the account ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. group_id Yes String User group ID.
For details about how to obtain a user group ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. project_id Yes String Project ID.
For details about how to obtain the agency ID, see Obtaining Account, IAM User, Group, Project, Region, and Agency Information. domain_id Yes String ID of the delegating account.