Creating a User and Granting Permissions

This section describes how to use IAM to implement fine-grained permissions control for your DMS resources. With IAM, you can:

If your account meets your permissions requirements, you can skip this section.

Figure 1 shows the process flow for granting permissions.

If users do not have the TMS Administrator permissions, the following situations occur:

  • Users cannot access the TMS console.
  • On consoles of other cloud services, users cannot view or use predefined tags created on the TMS console.

Prerequisites

Before granting permissions, learn about the TMS permissions and select the permissions as required. For details about the system-defined permissions in RBAC supported by TMS, see TMS Permissions. To grant permissions for other services, learn about all permissions.

Process Flow

Figure 1 Process for granting TMS permissions
  1. create a user group and grant it permissions (TMS Administrator as an example).

  2. Create an IAM user and add it to the created user group.

  3. Log in and verify permissions.

    Log in to the TMS console as the created user, and verify that it only has the TMS Administrator permissions.