CreateAccessAssignment
Configures the users or groups that are allowed to access an account in a resource directory, along with the corresponding access permissions (access configurations).
Operation description
This is an asynchronous operation. You can use the TaskId parameter in the response to invoke GetTask to query the task execute status.
For more information about multi-account authorization on accounts in a resource directory, see Overview of multi-account authorization.
This topic provides an example of how to provision the access configuration ac-00jhtfl8thteu6uj**** for the CloudSSO user u-00q8wbq42wiltcrk**** on the account in a resource directory 114240524784****, so that the CloudSSO user can access authorized resources in the account.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cloudsso:CreateAccessAssignment |
create |
*AccessConfiguration
User
Group
*Account
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| DirectoryId |
string |
Yes |
The directory ID. |
d-00fc2p61**** |
| AccessConfigurationId |
string |
Yes |
The access configuration ID. |
ac-00jhtfl8thteu6uj**** |
| TargetType |
string |
Yes |
The type of the task target. Valid values:
|
RD-Account |
| TargetId |
string |
Yes |
The ID of the deployment target. |
114240524784**** |
| PrincipalType |
string |
Yes |
The type of the CloudSSO identity. Valid values:
|
User |
| PrincipalId |
string |
Yes |
The ID of the CloudSSO identity. Valid values:
|
u-00q8wbq42wiltcrk**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response. |
||
| Task |
object |
The task information. |
|
| Status |
string |
The task status. Valid values:
|
InProgress |
| TaskId |
string |
The task ID. |
t-sh6tceylhvgejpip**** |
| PrincipalId |
string |
The ID of the CloudSSO identity. |
u-00q8wbq42wiltcrk**** |
| TargetPath |
string |
The path ID of the task target in the resource directory. |
rd-3G****/r-Wm****/114240524784**** |
| PrincipalName |
string |
The name of the CloudSSO identity. |
Alice |
| TargetName |
string |
The name of the task target. |
dev-test |
| TargetId |
string |
The ID of the task target. |
114240524784**** |
| AccessConfigurationName |
string |
The name of the access configuration. |
ECS-Admin |
| TargetPathName |
string |
The path name of the task target in the resource directory. |
rd-3G****/root/dev-test |
| TaskType |
string |
The type of the task. Valid values:
|
CreateAccessAssignment |
| TargetType |
string |
The type of the task target. Valid values:
|
RD-Account |
| AccessConfigurationId |
string |
The access configuration ID. |
ac-00jhtfl8thteu6uj**** |
| PrincipalType |
string |
The type of the CloudSSO identity. Valid values:
|
User |
| OriginTargetId |
string |
114240524784**** |
|
| RequestId |
string |
The request ID. |
4726AA56-E138-5C99-85E4-F493536D042F |
Examples
Success response
JSON format
{
"Task": {
"Status": "InProgress",
"TaskId": "t-sh6tceylhvgejpip****",
"PrincipalId": "u-00q8wbq42wiltcrk****",
"TargetPath": "rd-3G****/r-Wm****/114240524784****",
"PrincipalName": "Alice",
"TargetName": "dev-test",
"TargetId": "114240524784****",
"AccessConfigurationName": "ECS-Admin",
"TargetPathName": "rd-3G****/root/dev-test",
"TaskType": "CreateAccessAssignment",
"TargetType": "RD-Account",
"AccessConfigurationId": "ac-00jhtfl8thteu6uj****",
"PrincipalType": "User",
"OriginTargetId": "114240524784****"
},
"RequestId": "4726AA56-E138-5C99-85E4-F493536D042F"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.