Step 2: Configure Identity Conversion Rules

As the enterprise administrator, you can manage identities and permissions of federated users in the enterprise identity provider. By configuring identity conversion rules, you can map the identities and permissions of federated users to the cloud system and control their access to specific resources.

  • Modifications to identity conversion rules will take effect only after the federated users log in again.
  • To modify the permissions of a federated user, modify the permissions of the user group to which the user belongs. Then restart the identity provider system for the modifications to take effect.

Prerequisites

An identity provider has been created in the cloud system, and the login link of the identity provider is accessible. (For details about how to create and verify an identity provider, see Step 1: Create an Identity Provider.)

Procedure

If you configure identity conversion rules by clicking Create Rule, IAM converts the rule parameters to the JSON format. Alternatively, you can click Edit Rule to configure rules in the JSON format.

Verifying Federated User Permissions

After configuring identity conversion rules, verify the permissions of federated users.

  1. Log in to the cloud system as a federated user, such as user ID1.

    On the Identity Providers page of the IAM console, click View in the row containing the identity provider. Copy the login link displayed on the identity provider details page, open the link using a browser, and then enter the username and password.

  2. Check that the federated user has the permissions assigned to the user group to which the user belongs.

    For example, an identity conversion rule has defined full permissions for all cloud services for federated user ID1 in the admin user group. On the management console, select any cloud service, and check if you can access the service.