doc-exports/docs/apm/umn/apm_07_0038.html
Li, Qiao 01222743d0 APM2.0 UMN 20230825 version
Reviewed-by: Mützel, Andrea <andrea.muetzel@t-systems.com>
Co-authored-by: Li, Qiao <qiaoli@huawei.com>
Co-committed-by: Li, Qiao <qiaoli@huawei.com>
2024-06-18 07:09:10 +00:00

24 lines
4.3 KiB
HTML

<a name="apm_07_0038"></a><a name="apm_07_0038"></a>
<h1 class="topictitle1">Creating a User and Granting Permissions</h1>
<div id="body8662426"><p id="apm_07_0038__en-us_topic_0000001088190833_p15821185717199">This chapter describes how to use IAM for fine-grained permissions control for your APM resources. With IAM, you can:</p>
<ul id="apm_07_0038__en-us_topic_0000001088190833_ul882255741919"><li id="apm_07_0038__en-us_topic_0000001088190833_li1822757101910">Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing APM resources.</li><li id="apm_07_0038__en-us_topic_0000001088190833_li682219578199">Manage permissions on a principle of least permissions (PoLP) basis.</li><li id="apm_07_0038__en-us_topic_0000001088190833_li282217576199">Entrust an account or cloud service to perform efficient O&amp;M on your APM resources.</li></ul>
<p id="apm_07_0038__en-us_topic_0000001088190833_p482245711191">If your account does not need individual IAM users, skip this chapter.</p>
<p id="apm_07_0038__en-us_topic_0000001088190833_p8822115715199">This section describes the procedure for granting permissions (see <a href="#apm_07_0038__en-us_topic_0000001088190833_fig132391629233">Figure 1</a>).</p>
<div class="section" id="apm_07_0038__en-us_topic_0000001088190833_section14379194242211"><h4 class="sectiontitle">Prerequisite</h4><p id="apm_07_0038__en-us_topic_0000001088190833_p1382216574191">Learn about the permissions supported by APM and choose policies or roles based on your requirements. For details, see <a href="apm_01_0007.html#apm_01_0007__en-us_topic_0000001195725122_section186901838201416">Permissions Management</a>. </p>
</div>
<div class="section" id="apm_07_0038__en-us_topic_0000001088190833_section0261321102319"><h4 class="sectiontitle">Process Flow</h4><p id="apm_07_0038__en-us_topic_0000001088190833_p10919131187"><strong id="apm_07_0038__en-us_topic_0000001088190833_b573145515310">Supported Cloud Services</strong></p>
<div class="fignone" id="apm_07_0038__en-us_topic_0000001088190833_fig132391629233"><a name="apm_07_0038__en-us_topic_0000001088190833_fig132391629233"></a><a name="en-us_topic_0000001088190833_fig132391629233"></a><span class="figcap"><b>Figure 1 </b>Process for granting APM permissions</span><br><span><img class="eddx" id="apm_07_0038__en-us_topic_0000001088190833_image133373410315" src="en-us_image_0000001218178520.png"></span></div>
<ol id="apm_07_0038__en-us_topic_0000001088190833_ol1382255717199"><li id="apm_07_0038__en-us_topic_0000001088190833_li1682215710191"><a name="apm_07_0038__en-us_topic_0000001088190833_li1682215710191"></a><a name="en-us_topic_0000001088190833_li1682215710191"></a><a href="https://docs.otc.t-systems.com/identity-access-management/umn/user_guide/user_groups_and_authorization/creating_a_user_group_and_assigning_permissions.html#en-us-topic-0046611269" target="_blank" rel="noopener noreferrer">Creating a User Group and Assigning Permissions</a><p id="apm_07_0038__en-us_topic_0000001088190833_p9823105718199">Create a user group on the IAM console, and assign the <strong id="apm_07_0038__en-us_topic_0000001088190833_b1719151851613">APM ReadOnlyAccess</strong> policy to the group.</p>
</li><li id="apm_07_0038__en-us_topic_0000001088190833_li482365771915"><a href="https://docs.otc.t-systems.com/identity-access-management/umn/user_guide/iam_users/creating_a_user.html#en-us-topic-0046611303" target="_blank" rel="noopener noreferrer">Creating a User</a><p id="apm_07_0038__en-us_topic_0000001088190833_p1582325714197">Create a user on the IAM console and add the user to the group created in <a href="#apm_07_0038__en-us_topic_0000001088190833_li1682215710191">1</a>.</p>
</li><li id="apm_07_0038__en-us_topic_0000001088190833_li482365718191"><a href="https://docs.otc.t-systems.com/identity-access-management/umn/user_guide/iam_users/logging_in_as_an_iam_user.html" target="_blank" rel="noopener noreferrer">Logging In as an IAM User</a> and Verifying Permissions<p id="apm_07_0038__en-us_topic_0000001088190833_p08237576198">Log in to the APM console using the created user, and verify that the user only has read permissions for APM.</p>
</li></ol>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="apm_07_0036.html">Permissions Management</a></div>
</div>
</div>