User management
User management lets you manage user accounts in the IDRS service. These accounts are imported from Resource Access Management (RAM) users.
Background information
Resource Access Management (RAM) is a permission management system provided by Alibaba Cloud.
RAM is primarily used to control access to your Alibaba Cloud resources. You can use RAM to create RAM users under your Alibaba Cloud account. You can then import these RAM users into the IDRS service console and grant them different permissions.
User types
Users in the IDRS service can have one of three roles. The following table describes each role and its permissions.
Role | Permissions |
Super administrator |
|
Administrator |
|
User |
|
View department list
Log on to the IDRS service console. In the navigation pane on the left, choose System Settings > User Management. The User Management page appears.
On the User Management page, you can view user information, import, edit, and delete users. You can also click the AK Management link to manage AccessKey information on the RAM user details page.
The user list contains the following information.
Username: The logon name of the user.
User Name: The user's display name.
Department: The department to which the user belongs. A user can belong to multiple departments.
Last Modified: The time when the user's information was last modified.
Role: The role of the user. Roles include super administrator, administrator, and user.
Actions: In this column, you can click Edit or Delete to edit or delete a user. You can also click AK Management to manage AccessKey information on the RAM user details page.
Import RAM users
Log on to the IDRS service console. In the navigation pane on the left, choose System Settings > User Management.
On the User Management page, click the Import RAM User button. The Import RAM User pane opens on the right.
Configure the following parameters:
Role: Select a user role from the drop-down list. Roles include super administrator, administrator, and user.
Department Name: Select a department for the user from the drop-down list. The departments in the list are created by a super administrator in Department Management. For more information, see Department management.
Select User: In the user list, select the check box next to one or more RAM users that you want to import.
After you configure the parameters, click OK to import the RAM users.
Edit a user
After you import a RAM user, you can edit the user's information, such as the role and department.
Follow these steps:
In the user list, find the user that you want to modify and click Edit in the Actions column. The Edit User pane appears.
Modify the user's Role or Department. A user can belong to one or more departments. Click Add Department to add a department for the user. To remove departments, select the departments that you want to remove and click the Remove Department button.
After you make your changes, click the OK button.
Delete a user
You can delete a user to revoke their permissions. To delete a user:
In the user list, find the user that you want to delete and click Delete in the Actions column.
In the confirmation dialog box, click the Confirm button to delete the watermark.
When you delete a user, the user is removed from the IDRS service only. The user is not deleted from RAM.
Manage AccessKeys
An AccessKey (AK) is a credential that a RAM user uses to access Alibaba Cloud resources through an API or other developer tools.
The AK Management link directs you to the RAM user details page. On this page, you can create, disable, and delete an AccessKey.
Follow these steps:
In the user list, find the target user and click AK Management in the Actions column. You are redirected to the user details page in the RAM console.
On the user details page, you can create, disable, or delete the user's AccessKey. For more information, see Create an AccessKey for a RAM user.