1.3. How to use User Access
The User Access feature is based on managing roles rather than by individually assigning permissions to specific users. In User Access, each role has a specific set of permissions. For example, a role might allow read permission for an application. Another role might allow write permission for an application.
You create groups that contain roles and, by extension, the permissions assigned to each role. You assign users (or service accounts) to groups. This means each user in a group is assigned the permissions of the roles in that group.
By creating different groups and adding or removing roles for that group, you control the permissions allowed for that group. When you add one or more users to a group, those users can perform all actions that are allowed for that group.
Red Hat provides two default access groups for User Access:
- Default admin access group. The Default admin access group is limited to Organization Administrator users in your organization. You cannot change or modify the roles in the Default admin access group.
Default access group. The Default access group contains all authenticated users in your organization. These users automatically inherit a selection of predefined roles.
注記You can make changes to the Default access group. However, when you do so, its name changes to Custom default access group.
Red Hat provides a set of predefined roles. Depending on the application, the predefined roles for each supported application might have different permissions that are tailored to the application.
1.3.1. The Default admin access group リンクのコピーリンクがクリップボードにコピーされました!
The Default admin access group is provided by Red Hat on the Red Hat Hybrid Cloud Console. It contains a set of roles that are assigned to all users who have an Organization Administrator role on your system. The roles in this group are predefined in the Red Hat Hybrid Cloud Console.
The roles in the Default admin access group cannot be added to or modified. Because this group is provided by Red Hat, it is automatically updated when Red Hat assigns roles to the Default admin access group.
The benefit of the Default admin access group is that it allows roles to be assigned automatically to Organization Administrators.
Additional resources