Create a permission set
A permission set is a template that defines the access permissions for CloudSSO users on accounts in a resource directory.
Procedure
-
Log on to the CloudSSO console.
-
In the left-side navigation pane, click Access Configuration.
-
On the Access Configuration page, click Create Access Configuration.
-
In the Create Access Configuration panel, set the following parameters and click OK.
-
Access Configuration Name: Required. The permission set name. Must be unique within the directory.
-
Session Duration: Optional. Maximum duration a user can stay logged in to a member account, in seconds. Valid values: 900 (15 minutes) to 43,200 (12 hours). Default: 3,600 (1 hour).
-
Relay State: Optional. The URL to redirect users to after sign-in. Must be a page in the Alibaba Cloud Management Console. Default: console homepage.
-
Description: Optional. A description for the permission set.
-
-
Configure system policies.
-
Use system policies
-
Select Use System Policy.
-
Select the required system policies.
-
Click Bind and Continue.
-
Click Next.
-
-
Do not use system policies
-
Select Do Not Use System Policy.
-
Click Continue.
-
-
-
Configure inline policies.
-
Click Create Inline Policy.
-
Enter a name for the inline policy and click OK.
-
Edit the inline policy content and click Update Inline Policy.
Inline policies use Resource Access Management (RAM) policy syntax. Basic elements of a permission policy.
-
-
Click close.
What's next
After you create the permission set, assign it to CloudSSO users on member accounts so they can access account resources. Assign access to a member account.