The page has been translated by Gen AI.

How-to guides

Using Cloud Control

The user must first create a landing zone to use the Cloud Control service. When a landing zone is created, you can use the management features of Cloud Control.

Caution
There is no charge for the Cloud Control service, but services used within Cloud Control such as Logging&Audit, Object Storage, Config Inspection, etc., may incur costs based on usage.

Create Landing Zone

To use Cloud Control in the Samsung Cloud Platform Console, you must first create a landing zone.

Follow these steps to create a landing zone.

  1. All Services > Management > Cloud Control Click the menu. 1. Navigate to the Service Home page of Cloud Control.

  2. Click the Create Landing Zone button on the Service Home page. 2. Go to the Create Landing Zone page.

  3. After setting the configuration items in the Rate Review and Organizational Unit Configuration area, click the Next button.

    Category
    required status
    Detailed description
    Home region-Home region of Cloud Control
    • Cloud Control designates the default region as the home region and cannot be changed
    • All regions except the default region are managed by Cloud Control
    Basic organizational unitRequiredEnter the primary organizational unit within the landing zone
    • Case-sensitive English letters, up to 128 characters
    • The primary organizational unit includes shared Accounts (Log Account, Audit Account)
    • Security: Name of the primary organizational unit for the shared Account
    • Can be modified after the landing zone is created
    Additional organizational unitRequiredEnter additional organizational unit within the landing zone
    • Case-sensitive English letters, enter up to 128 characters
    • Can be added after the landing zone is created
    Table. Landing zone creation - cost review and organizational unit configuration items

  4. After setting the configuration items in the Shared Account Configuration area, click the Next button.

    Category
    Required status
    Detailed description
    Management Account-The Management Account name is displayed and cannot be edited.
    Log AccountRequiredEnter Log Account information
    • Account name: Korean, English, numbers, spaces, special characters(+=-_@[](),.) using them, enter within 3 to 30 characters
    • Email: Enter up to 60 characters in a valid email address format
    • Email confirmation: Re-enter the email address entered in Email
    Audit AccountRequiredEnter Log Account information
    • Account name: Korean characters, English letters, numbers, spaces, and special characters (+=-_@[](),.) using 3 to 30 characters
    • Email: Enter up to 60 characters in a valid email address format
    • Email Confirmation: Re-enter the email address entered in Email
    • The same email as Log Account cannot be used
    Table. Landing Zone Creation - Shared Account Configuration Items
    Reference
    • Log Account is a repository of logs for API activity and resource configurations collected from all Accounts. * Log Account cannot be changed.
    • The Audit Account is a restricted account, and the security and compliance team can obtain access to all accounts within the organization through the Audit Account.

  5. After setting the configuration items in the Additional Configuration area, click the Next button.

    Category
    Required status
    Detailed description
    Account access configurationRequiredSelect a method to manage access to the Account
    • Account access via ID Center
      • Configure users who perform specific tasks in the Account by creating pre-configured groups and permission sets
      • Automatically assign users when provisioning an Account with Account Factory or registering an existing Account
      • Selectable only when using ID Center’s own directory
    • Self-managed Account access
      • Cloud Control does not create directory groups or permission sets for the landing zone
      • Automatically assign users when provisioning an Account with Account Factory or registering an existing Account
      • Manage access to the Account via ID Center or other Account access methods
    Trail configuration-Proceed with automatic configuration
    Detection guardrailSelectionSelect whether to enable the detective guardrail
    • When the detective guardrail is enabled, it applies only to the default organizational unit
    • Even after creating a landing zone, you can change settings on the Landing Zone Settings page
    Table. Create Landing Zone - Additional Configuration Items

  6. In the Check Input Information area, after reviewing the landing zone configuration information and Service Permissions, check the agreement regarding permissions and guidelines.

  7. Click the Create button. 5. A popup window announcing the creation of a landing zone opens.

  8. After checking the information about creating a landing zone, click the Confirm button. 6. The landing zone creation request has been completed.

    • Creating a landing zone takes some time, and a notification is sent when the task is completed.
    • Once the landing zone creation is complete, you can view the full menu of Cloud Control and the organization status on the Service Home page.
Caution
  • You cannot cancel while creating a landing zone.
  • If creating the landing zone fails, delete the landing zone and then create it again.
  • When Account Access Configuration is selected as Self-Managed Account Access, the Access Portal URL and User Credentials information cannot be viewed.
Reference

When a landing zone is created, you can verify the following in Cloud Control.

  • Two organizational units: shared Account, an organizational unit for the Account that the user will provision.
  • Two shared Accounts: isolated Account for log archiving and security auditing
  • Selected IAM management configuration
  • 10 preventive guardrails: settings for policy enforcement
  • Enable control policies for the Organization service

Check detailed landing zone information

Landing Zone Settings page allows you to view detailed information about the landing zone.

information
After creating a landing zone, you can view and edit its details.

To view detailed information about the landing zone, follow these steps.

  1. All Services > Management > Cloud Control Click the menu. 1. Navigate to the Service Home page of Cloud Control.
  2. Service Home on the page, click the Landing Zone Settings menu. 2. Navigate to the Landing Zone Settings page.
CategoryDetailed description
ServiceService name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
  • In Cloud Control, it refers to the SRN of the resource type
Resource nameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation date and timeService creation date and time
ModifierUser who edited the service information
Modification date and timeDate and time the service information was modified
Home regionLanding zone home region information
Account access configurationHow to manage access to an Account
Trail configurationTrail configuration enablement
  • active state maintenance
Detection guardrailDetection guardrail activation status
  • Active: Create account diagnostics under the registered organizational unit and enable scheduling
    • Display detection guardrail pricing, checklist, diagnostic cycle, and start time information
  • Inactive: Delete diagnostics for all accounts within the organizational unit
  • Click the Edit button to change the activation status
    • Changes cannot be canceled after request
Delete landing zoneDelete the landing zone
Table. Landing zone configuration items

Delete Landing Zone

If you fail to create a landing zone or do not use it, you can delete the landing zone.

Caution
  • Deleted resources cannot be recovered.
  • Organization units, Account, buckets, ID Center resources are not deleted automatically.
    • When recreating a landing zone, to use the same name as an existing, non‑deleted resource, you must first delete the existing resource before creating the landing zone.
    • Existing resources can be deleted individually from the Organization, Object Storage, and ID Center services.

To delete a landing zone, follow these steps.

  1. Click the All Services > Management > Cloud Control menu. 1. Go to the Service Home page of Cloud Control.
  2. On the Service Home page, click the Landing Zone Settings menu. 2. Navigate to the Landing Zone Settings page.
  3. On the Landing Zone Settings page, click the Delete Landing Zone button. 3. Delete Landing Zone popup opens.
  4. Landing Zone Deletion After entering the Cloud Contorl ID displayed in the popup into the deletion confirmation area, click the Confirm button. 4. The landing zone deletion request has been completed.
    • While deleting a landing zone, an explanation regarding the landing zone deletion process is displayed on the Service Home page.

Managing organizational units and Accounts

You can view the list of organizational units and accounts, register them in Cloud Control, and manage them.

To view and manage organizational units and the Account list, follow the steps below.

  1. Click the All Services > Management > Cloud Control menu. 1. Navigate to the Service Home page of Cloud Control.
  2. On the Service Home page, click the Organization menu. 2. Navigate to the Organization Unit and Account Management page.
  3. Select the view mode at the top right of the Organization Unit and Account Management page.
    • Click the View Hierarchy button to view and manage organizational units and Accounts in a hierarchical structure.
      CategoryDetailed description
      Create a sub-organization unitAdd a new organizational unit under the selected organizational unit
      • Enabled only when a single organizational unit is selected in the hierarchy
      MoreYou can manage organization units or register a new Account
      • Organization Unit: Deletion/registration/re-registration of organization units, and application/removal of detective guardrails possible
      • Account: Account registration/deregistration possible
      Organization Unit/Account NameDisplay the names of organizational units and Accounts in a measurement-structure format
      • +, - buttons can be clicked to expand or collapse the hierarchy
      • Clicking an organizational unit/Account name navigates to the detail page
      ID/emailOrganization units display the ID, and Account displays the ID and email
      statusCloud Control registration status for organization units or Accounts
      • Registered, Not registered, Registering, Registration failed
      • No status displayed when Root
      Register organization unitCloud Control registration status of sub‑organization units
      • Number of registered organization units / total organization units displayed
      Register AccountSub Account’s Cloud Control registration status
      • registered Account count / total Account count displayed
      Detection guardrailDetection guardrail application status for organizational units or sub-units
      Table. Hierarchy view items
    • View Account List: You can view and manage the list of Accounts that constitute Cloud Control.
      CategoryDetailed description
      Account registrationRegister the selected Account from the Account list to Cloud Control
      • When you select an Account in the Account list that is Unregistered, Registration Failed status, it becomes active
      More > Unregister AccountDeregister the selected Account from the Account list
      • When you select an Account in the Account list that is in registered, registration failed status, it becomes active
      • Shared Accounts cannot be deregistered
      Account nameAccount name
      Account IDAccount ID
      emailAccount user email
      statusCloud Control registration status of an organization unit or Account
      • Registered, Not registered, Registering, Registration failed
      • When Root, no status is displayed
      Table. Account list view item
    • Create Account button click allows you to create a new Account. * For more details, refer to Account 생성하기.

Check organization and Account detailed information

You can view and edit the detailed information of organizational units and Account. To view detailed information of the organization unit and Account, follow these steps.

  1. All Services > Management > Cloud Control Click the menu. 1. Go to the Service Home page of Cloud Control.
  2. On the Service Home page, click the Organization menu. 2. Navigate to the Organization Unit and Account Management page.
  3. Click the View Hierarchy button on the Organization Unit and Account Management page.
  4. Click the resource name in the hierarchical list to view its details. 4. Navigate to the detailed page of the resource.

Root detailed information

On the Root Details page, you can view and manage the detailed information of the organization Root and the list of subordinate Accounts. The Root Details page consists of Basic Information, Sub Account tabs.

Basic Information

You can view basic information about the Root organization and the number of organizational units and Accounts registered in Cloud Control.

CategoryDetailed description
ServiceService name
Resource TypeService type
SRNUnique resource ID in Samsung Cloud Platform
Resource nameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation date and timeService creation date and time
ModifierUser who edited the service information
Modification date and timeDate and time the service information was modified
Register organization unitCloud Control registration status of sub-organizations under Root
  • displayed as registered organizational units / total organizational units
Register AccountCloud Control registration status of Accounts under Root
  • displayed as registered Account count / total Account count
Table. Root Details - Basic Information Tab Items

Sub Account

You can view and manage the list of Accounts under the Root and the registration status of Cloud Control.

CategoryDetailed description
Account registrationRegister the selected Account from the Account list to Cloud Control
  • When you select an Account in the unregistered state from the Account list, it becomes active
Account nameAccount name
emailAccount user email
statusCloud Control registration status of an organization unit or Account
  • Registered, Not registered, Registering, Registration failed
  • When Root, no status is displayed
Table. Root Details - Sub Account Tab Items

Organization Unit Detailed Information

On the Organization Unit Details page, you can view and manage the detailed information of the organization unit, its subordinate Accounts, and the applied preventive guardrails and detection guardrails. Organization Unit Details page consists of Basic Information, Sub Account, Preventive Guardrails, Detection Guardrails tabs.

Basic Information

You can view basic and detailed information about the organizational unit.

CategoryDetailed description
ServiceService name
Resource TypeService type
SRNUnique resource ID in Samsung Cloud Platform
Resource nameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation date and timeService creation date and time
ModifierUser who edited the service information
Modification date and timeDate and time the service information was modified
Organization Unit NameName of the organizational unit
Apply guardrailsNumber of guardrail types applied to the current organizational unit
  • Prevention: Number of applied preventive guardrails
  • Detection: Types of detection guardrails
Register organization unitCurrent organization unit’s Cloud Control registration status of sub-units
  • Number of registered organization units / total organization units displayed
Register AccountCurrent Cloud Control registration status of sub-accounts under the organization unit
  • displayed as registered account count / total account count
Higher-level organization unitHierarchy of the parent organizational units for the current unit
Apply detection guardrail / Remove detection guardrailChange the detection guardrail application status at the organizational unit level
  • When the button is clicked, you can apply or remove the detection guardrail
Re-registrationRe-register the current organization unit in Cloud Contorl
Table. Organization Unit Details - Basic Information Tab Items

Sub Account

You can view and manage the list of subordinate Accounts for an organizational unit.

Information
For Security organizational units, Accounts cannot be registered.
CategoryDetailed description
Account registrationRegister the selected Account from the Account list to Cloud Control
  • When you select an Account in the unregistered state from the Account list, it becomes active
Account nameAccount name
emailAccount user email
statusCloud Control registration status of an organization unit or Account
  • Registered, Not registered, Registering, Registration failed
  • When Root, no status is displayed
Table. Organization Unit Details - Sub Account Tab Items

Preventive Guardrail

You can view and manage the list of preventive guardrails applied at the organizational level.

Information
For Security organizational units, guardrails cannot be applied or removed.
CategoryDetailed description
Target Service NameName of the service to which the guardrail applies
Guardrail nameGuardrail name
  • Clicking the guardrail name allows you to view detailed information about that guardrail
typeApplication method
Application methodGuardrail application method display
  • Inheritance method, click to view detailed organizational unit name
DisableDisable the selected guardrail from the guardrail list
  • Enable when a guardrail is selected in the guardrail list
Apply preventive guardrailsNew preventive guardrails can be applied to organizational units
  • When the button is clicked, navigate to the Preventive Guardrail Apply page
Table. Organization Unit Details - Prevention Guardrail Tab Items

Detection Guardrail

You can view and manage the diagnostic results of detection guardrails applied at the organizational level.

Reference
Accounts with diagnostic history in Cloud Control are provided with the latest diagnostic results regardless of whether detection guardrails are applied.
CategoryDetailed description
Account nameAccount name to be diagnosed
Diagnosis nameDiagnosis Name
PASSNumber of checklist items with a PASS (normal) diagnosis result
FAILNumber of checklist items with a diagnosis result of FAIL (vulnerable)
CHECKNumber of checklist items with a diagnosis result of CHECK (verification required)
ERRORNumber of items in the checklist whose diagnosis result is ERROR (diagnosis not possible)
N/ANumber of checklist items with a diagnosis result of N/A (not applicable)
AllTotal number of checklist items
Diagnosis ResultDiagnosis request result
  • Completed: The diagnosis request has been successfully completed, and clicking will navigate to the detail page
  • Error: The diagnosis request was not completed successfully, so detailed information cannot be viewed
Diagnosis date and timeDiagnosis request date and time
Table. Diagnosis result list items

Check detailed information of Account

Account Details page allows you to view the account’s detailed information and the list of applied preventive guardrails. Account Details page consists of Basic Information, Preventive Guardrails tabs.

Basic Information

You can view basic and detailed information about the organization unit.

CategoryDetailed description
ServiceService name
Resource TypeService type
SRNUnique resource ID in Samsung Cloud Platform
Resource nameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation date and timeService creation date and time
ModifierUser who edited the service information
Modification date and timeDate and time the service information was modified
emailAccount user email
Apply GuardrailsNumber of guardrail types applied to the current organizational unit
  • Prevention: Number of applied preventive guardrails
  • Detection: Types of detection guardrails
ID Center usernameID Center user email
Higher-level organization unitCurrent account’s parent organizational unit hierarchy
RegisterThe organization unit of the current Account can be changed
Table. Account Details - Basic Information Tab Items

Preventive Guardrail

You can view the list of preventive guardrails applied to the Account.

CategoryDetailed description
Target Service NameName of the service to which the guardrail applies
Guardrail nameGuardrail name
  • Clicking the guardrail name allows you to view detailed information about that guardrail
typeApplication method
Application methodGuardrail application method display
Table. Account Details - Preventive Guardrail Tab Items

Check Access Portal Connection Information

User and Access page allows you to view the Access Portal connection URL and connection methods (password, SSO, MFA).

information
User and Access information is not displayed when creating a landing zone if Account Access Configuration is set to Self-managed Account Access. Select Account access via ID Center to create a landing zone.

To check the Access Portal connection information, follow these steps.

  1. Click the All Services > Management > Cloud Control menu. 1. Go to the Service Home page of Cloud Control.
  2. On the Service Home page, click the User and Access menu. 2. Navigate to the User and Access page.
  3. Check the information in the User and Access page’s Integrated Access Management area.
CategoryDetailed description
Access typeMethod for accessing the Access Portal
Access Portal URLAccess Portal connection URL
  • URL When the URL is clicked, Access Portal login page opens in a new tab
  • Can be accessed using the ID login credentials of ID Center
Permission setA collection of administrator policies used by ID Center to determine the valid permissions of users who can access a specific account
Table. Shared Account item
Reference
For detailed information about credential sources and ID Center, see ID Center.
Guide

If the landing zone is configured with a self-managed Account access, see the following.

  • Cloud Control does not automatically create directory groups or permission sets.
  • When provisioning an Account with the Account factory or registering an existing Account, the user is assigned automatically.
  • You can manage access to an Account via ID Center or other Account access methods.

Check user credential information

User and Access page lets you view the user credential source type and the ID Center ID.

Information
User and Access information is not displayed when creating a landing zone if Account Access Configuration is set to Self-Managed Account Access. Select Account access via ID Center to create a landing zone.

To verify user credential information, follow the steps below.

  1. All Services > Management > Cloud Control Click the menu. 1. Navigate to the Service Home page of Cloud Control.
  2. On the Service Home page, click the User and Access menu. 2. Navigate to the User and Access page.
  3. Check the information in the User Credential Management area of the User and Access page.
CategoryDetailed description
Credential sourceCredential source types configured in ID Center
  • ID Center’s own directory: Directory within ID Center
  • AD (Active Directory): Active Directory managed directly by the user
ID Center IDClicking the ID Center’s ID
  • ID takes you to the ID Center Settings page
User GroupA group formed to classify workers who perform specific tasks within an organization.
Table. User Credential Management Items
Reference
  • For details about credential sources and ID Center, see ID Center.
  • Management > IAM You can add users and user groups in the service. * For more details, refer to IAM.
Overview
Managing Guardrails