第2章 Procedures for configuring User Access
As an Organization Administrator or User Access administrator, you can click
> Identity & Access Management to view, configure, and modify the User Access groups, roles, and permissions.
2.1. Creating a User Access administrator リンクのコピーリンクがクリップボードにコピーされました!
The User Access administrator role is assigned by the Organization Administrator and used for user and group management tasks that apply to managing human users and service accounts. All users in the group with the User Access administration role permissions can add, modify, or delete groups and roles. The User Access administrator role does not inherit the roles defined in the Default Admin Access group.
The User Access administrator role cannot create or modify a User Access administrator group. Only the Organization Administrator can create, modify, or delete a group that is assigned the User Access administrator role.
The User Access administrator role does not grant permission to view and approve customer Access Requests.
This role is not allowed to do the following:
- Assign the Organization Administrator role.
- Add members, either users or service accounts, to any group assigned the User Access administrator role.
- Create new groups and assign the User Access administrator role to the group.
These restrictions are intentionally enforced to uphold the core cybersecurity Principle of Least Privilege and secure the administrative tier from allowing a higher level of permissions than are needed to perform the User Access administrator tasks.
Prerequisites
- You are logged in to the Red Hat Hybrid Cloud Console as a user who has Organization Administrator permission.
Procedure
- Navigate to the Red Hat Hybrid Cloud Console > Settings > Identity & Access Management > User Access > Groups.
- Click Create group.
Follow the guided actions provided by the wizard to create the group and add users and roles.
- Name the group with a recognizable name: User Access Admin.
- Provide a meaningful description: User Access Organization Administrator permissions
- Click the Next button to add roles.
- Search for the User Access administrator role and click the selection box to add this role to the group. Optionally, select additional roles.
Click the Next button to add members to the group.
注記Any member you add must be an active member of the organization account.
- After you select the members for the group, click the Next button to review the details.
- You can click the Back button to go back and make changes, or the Cancel button to cancel the action.
- Click the Submit button to complete the Create group wizard. The new group will appear in the Groups tab.