2.5. Restricting service access to a single user
You can create a new group that contains a single user and add a role to that group. The role you add provides the service access permissions you want that single user to have. If you add other users to the group, the added users will have the same group permissions.
The roles you add to the group can be from the predefined list of roles provided with User Access, from custom roles created by an Organization Administrator, or a combination of both.
For more information about predefined roles, see section Predefined User Access roles.
When you add a user to a new group, the user acquires the permissions of the new group and also inherits the permissions of all other groups they belong to. The permissions of the new group are added to their existing permissions.
In this procedure you modify the Default access group. Once modified, the Default access group name changes to Custom default access. The Custom default access group is no longer updated with changes pushed out by Red Hat from the Red Hat Hybrid Cloud Console.
You can restore the Default access group, which removes the Custom default access group and any changes you made. See Restoring the Default access group.
Prerequisites
- You are logged in to the Red Hat Hybrid Cloud Console as a user who has Organization Administrator permission.
- If you are not an Organization Administrator, you must be a member of a group that has the User Access administrator role assigned to it.
Procedure
- Navigate to the Red Hat Hybrid Cloud Console > Settings > Identity & Access Management > User Access > Groups. The Groups page is displayed.
Remove all roles from the Default access group.
Because all users in your organization belong to the Default access group, you cannot add or remove single users in Default access to create access control. By removing all roles, users do not inherit role permissions from Default access.
- Select the checkbox above the roles list to select all roles in the group.
- Click the more options icon (⋮) > Remove.
- Click Remove roles to confirm.
- Save the changes to Default access group. The name changes to Custom default access.
Create a new group that contains the users and roles for the allowed access permissions.
For example, create a group Security Admin that contains the users who will have full access to vulnerability service.
- Create a group Security Admin.
- Add one or several users to the group from the Members list.
Add the Vulnerability administrator role.
Each user you add to this group has full access to the vulnerability service.
注記If you want an Organization Administrator to have access, add the Organization Administrator user to the group.