tencent cloud

Tencent Cloud Organization

Product Introduction
Overview
Concepts
Purchase Guide
Operation Guide
Console Overview
Organization Settings
Department Management
Member Account Management
Member Finance Management
Member Access Management
Resource Management
Member Audit
Identity Center Management
API Documentation
History
Introduction
API Category
Making API Requests
Organization Settings APIs
Department and Member Management APIs
ListOrganizationIdentity
Unified Member Login APIs
Organization Service Management APIs
Organization Management Policy APIs
Resource Sharing APIs
Identity Center Management APIs
Identity Center User Management APIs
Identity Center User Group Management APIs
Identity Center Management SCIM Synchronization APIs
Identity Center Single Sign-On Management APIs
Identity Center Permission Configuration Management APIs
Identity Center Multi-Account Authorization Management APIs
Identity Center Sub-User Synchronization Management APIs
Data Types
Error Codes
TCO API 2018-12-25
Related Agreement
Statement of Tencent Cloud Customers’ Tencent Cloud Organization
FAQs
Concept
Basic
Operation
Glossary

Overview of Multi-Account Authorization

PDF
聚焦模式
字号
最后更新时间: 2024-07-31 14:17:23
On the multi-account authorization page, you can configure Cloud Access Management (CAM) user synchronization and CAM role synchronization based on the directory structure of the organization account.

Difference Explanation

Identity Center users can access the account's cloud resources through CAM roles or CAM users. The differences between the two methods are shown in the table below.
Access Method
Description
Synchronization Method
Related Documentation
Configuring CAM Role Synchronization
Enterprises manage users accessing Tencent Cloud in the Tencent Cloud Organization's Identity Center. Through permission configuration and CAM role synchronization, users can log in to member accounts using single sign-on (SSO) and access the CAM roles within those accounts, and then access the cloud resources of the member account.
When configuring CAM role synchronization, the Identity Center will initiate tasks for each triplet (user-account-permission configuration).
After synchronization, the access permissions in CAM are finalized and cannot be modified in CAM.
Configuring CAM User Synchronization
Enterprises manage users accessing Tencent Cloud in the Tencent Cloud Organization's Identity Center. Through CAM user synchronization, users can log in to member accounts and access the CAM users within those accounts, and then access the cloud resources of the member account.
When configuring CAM user synchronization, the Identity Center will initiate tasks for each tuple (user-account).
After synchronization, the access permissions in CAM are empty and need to be configured in CAM.

CAM Role Synchronization Explanation

If you need to perform a one-time batch authorization for multiple accounts, multiple identities, and multiple access configurations, you can go to TCO > Identity Center, enter the multi-account permission management page, view the account directory tree, and perform the following operations:
1. Select one or more accounts in the account tree as authorization targets.
2. Select one or more Identity Center identities.
3. Select one or more access configurations.
4. Click Configure CAM Role Synchronization, and the Identity Center service will complete the authorization for you in batches.
In batch authorization, if duplicate authorization is attempted for some existing authorizations, the operation will fail. However, newly added authorizations in the same batch will succeed.
Each time permissions are added, the Identity Center will initiate an asynchronous task for each triplet (identity-account-permission configuration).

CAM User Synchronization Explanation

If you need to perform a one-time batch authorization for multiple accounts and multiple identities, you can go to TCO > Identity Center, enter the multi-account permission management page, view the account directory tree, and perform the following operations:
1. Select one or more accounts in the account directory tree.
2. Select one or more Identity Center identities.
3. Click Configure CAM User Synchronization, and the Identity Center service will complete the synchronization for you in batches.
In batch synchronization, if a duplicate operation is attempted for some existing synchronizations, the operation will fail. However, newly added synchronizations in the same batch will succeed.
After successful configuration, a CAM user with the same name as the Identity Center user will be created in the target account.
Authorization: Access the target account to authorize the CAM user created in the previous step.
CAM users have no permissions by default. You need to grant them the appropriate permissions for the corresponding resources.
Identity Center users access the authorized resources in the target account through the CAM user identity.
For specific operations, see Configuring CAM User Synchronization.





帮助和支持

本页内容是否解决了您的问题?

填写满意度调查问卷,共创更好文档体验。

文档反馈