Overview
CDNetworks Console IAM provides you can create Custom Policies that have lists of permission that are explicitly tied to user accounts and actions to perform the functional operations of each product and your service resource.
- Admins assign roles to end-users based on what that end-users need to do, and what functions they need to do, but end-users don’t use some functions out of boundary roles in your organization.
- CDNetworks Console IAM provides Custom Policy features that help you define the permission is the smallest actions as you need to tie when Admins use Main Account or Sub Account have the same role to manage IAM.
- This article describes how to create a function policy and how to create an expression policy for UC.
Category |
Product |
Description |
Create function policy |
CDN/Cloud Security Product |
Create Custom Policy for CDN/Cloud Security Product |
Create expression policy |
UC(IAM) |
Create Custom Policy for UC (control-group management, Access Key Management, Contact Management, and others) |
Instruction
Create a function policy (for CDN/Security products)
- This procedure explains how to create a function policy for CDN/Security products.
- Create policy
- Choose creation way:
- Fill in policy name and note, click add policy
- Choose actions whether allowed or denied and click save to create a new custom policy.
Creating expression Policy for UC
- This procedure explains how to create an expression policy (usually for non-CDN/Security products)
- Create policy
- Choose creation way
- Fill in policy name and note, in the Configuration Mode section, select Visualized or Script.
- If you select Visualized, click 【Add Policy】. In the dialog box that appears, specify the permission effect, product/service, actions, and resources, and then click 【Save】.
- If you select Script, edit the policy in the Policy Document section. For more information, see the chapter of Expression Policy structure
- Click OK