The user must first create a landing zone to use the Cloud Control service. If a landing zone is created, you can use the management functions of Cloud Control.
Create Landing Zone
To use Cloud Control in the Samsung Cloud Platform Console, you must first create a landing zone.
To create a landing zone, follow the steps below.
All Services > Management > Cloud Control Click the menu. Navigate to Cloud Control’s Service Home page.
Click the Landing Zone Creation button on the Service Home page. You will be taken to the Landing Zone Creation page.
Fee Review and Organizational Unit Configuration area, after setting the configuration items, click the Next button.
Category RequiredDetailed description Home Region - Home Region of Cloud Control - Cloud Control designates the default region as the Home Region and cannot be changed
- All regions other than the default region are under Cloud Control’s management
Basic Organizational Unit Required Enter basic organizational unit within landing zone - Case-sensitive English letters, enter within 128 characters
- Basic organizational unit includes shared Accounts (Log Account, Audit Account)
- Security: Name of the basic organizational unit for shared Account
- Can be modified after landing zone creation
Additional Organizational Unit Required Enter additional organizational unit within landing zone - Case-sensitive English letters, enter within 128 characters
- Can be added after landing zone creation
Table. Landing Zone Creation - Fee Review and Organizational Unit Configuration ItemsShared Account Configuration After setting the configuration items in the area, click the Next button.
Category RequiredDetailed description Management Account - Management Account name is displayed and cannot be edited Log Account Required Log Account information input - Account name: Use Korean, English, numbers, spaces, special characters(
+=-_@[](),.) to input within 3 ~ 30 characters
- Email, Confirm Email: Input within 60 characters according to email address format
Audit Account Required Enter Log Account information - Account name: Use Korean, English, numbers, spaces, special characters(
+=-_@[](),.) and enter within 3 to 30 characters
- Email, Confirm Email: Enter within 60 characters following email address format
- Cannot use the same email as Log Account
Table. Landing Zone Creation - Shared Account Configuration Items- Account name: Use Korean, English, numbers, spaces, special characters(
- Log Account is a repository of logs of API activity and resource configuration collected from all Accounts. Log Account cannot be changed.
- Audit Account is a limited account, and the security and compliance team can obtain access rights to all accounts within the organization through the Audit Account.
Additional configuration area, after setting the configuration items, click the Next button.
Category RequiredDetailed description Account access configuration Required Select method to manage access to the Account - Account access via ID Center: Create pre-configured groups and permission sets to configure users who perform specific tasks in the Account
- Automatically assign users when provisioning an Account with Account Factory or registering an existing Account
- Self-managed Account access: Manage access to the Account via ID Center or other Account access methods
- Cloud Control does not create directory groups or permission sets for the landing zone
- No user creation when provisioning an Account with Account Factory or registering
Trail configuration - Automatic configuration in progress Table. Landing Zone Creation - Additional Configuration Items- Account access via ID Center: Create pre-configured groups and permission sets to configure users who perform specific tasks in the Account
Input Information Check area, after checking the landing zone configuration information and Service Permissions, check the agreement content for permissions and guidelines.
Click the Complete button. A popup window notifying the creation of the landing zone will open.
After checking the information about creating a landing zone, click the Confirm button. The landing zone creation request is completed.
- Landing zone creation takes some time, and a notification will be sent when the task is completed.
- When the landing zone creation is complete, you can check the full menu of Cloud Control and the organization status on the Service Home page.
- You cannot cancel while creating a landing zone.
- If you fail to create a landing zone, delete the landing zone and then create it again.
When a landing zone is created, you can check the following items in Cloud Control.
- Two organizational units: shared Account, organizational unit for the Account that the user will provision
- Shared Account 2: Log Archive and Security Audit Isolation Account
- Selected IAM management configuration
- 10 preventive guardrails: Settings for policy application
- Organization Service Control Policy Activation
Check detailed landing zone information
Landing Zone Settings page allows you to view detailed information about the landing zone.
To check the detailed information of the landing zone, follow the steps below.
- All Services > Management > Cloud Control Click the menu. Navigate to Cloud Control’s Service Home page.
- Service Home on the page click the Landing Zone Settings menu. Navigate to the Landing Zone Settings page.
| Category | Detailed description |
|---|---|
| service | service name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform
|
| Resource Name | Resource Name |
| Resource ID | Unique resource ID in the service |
| Creator | User who created the service |
| Creation time | Service creation time |
| Modifier | User who edited the service information |
| Modification Date | Date Service Information Was Modified |
| Home Region | Home region information of the landing zone |
| Account Access Configuration | How to manage access for Account |
| Trail configuration | Trail configuration activation status
|
| Landing Zone Delete | Delete landing zone
|
Delete landing zone
If you fail to create a landing zone or do not use it, you can delete the landing zone.
- Deleted resources cannot be recovered.
- Organization unit, Account, bucket, ID Center resources are not automatically deleted.
- If you want to use the same name as an existing resource that hasn’t been deleted when recreating a landing zone, you must delete the existing resource directly before creating the landing zone.
- Existing resources can be deleted individually from the Organization, Object Storage, and ID Center services.
To delete the landing zone, follow the steps below.
- All Services > Management > Cloud Control Click the menu. Navigate to Cloud Control’s Service Home page.
- Click the Landing Zone Settings menu on the Service Home page. You will be taken to the Landing Zone Settings page.
- Landing Zone Settings page, click the Landing Zone Delete button. Landing Zone Delete popup opens.
- Landing Zone Deletion displayed in the popup window, enter the Cloud Contorl ID into the deletion confirmation area, then click the Confirm button. The landing zone deletion request is completed.
- While deleting the landing zone, a description about the landing zone deletion process is displayed on the Service Home page.
Managing Organization Units and Accounts
You can check the list of organization units and accounts, and register and manage them in Cloud Control.
To view and manage the organization unit and Account list, follow the steps below.
- All Services > Management > Cloud Control Click the menu. Navigate to Cloud Control’s Service Home page.
- Service Home page, click the Organization menu. Move to the Organization unit and Account management page.
- Organization Unit and Account Management Select the view mode located at the top right of the page.
| Category | Detailed description |
|---|---|
| View Hierarchy | Display organizational units in a hierarchical structure |
| Account List View | Display Account list within organization |
| Account creation | Create a new Account
|
View Hierarchy
Organizational Unit and Account Management page, when you click the View Hierarchy button, you can view and manage organizational units and accounts in a hierarchical structure.
| Category | Detailed description |
|---|---|
| Create Sub-Organization Unit | Add a new organization unit under the selected organization unit
|
| More | Manage organizational units or register a new Account
|
| Organization Unit/Account Name | Display organization unit and account names in a measurement structure format
|
| ID/email | Organization unit shows ID, Account shows ID and email |
| Status | Organization unit or Account’s Cloud Control registration status
|
| Registered organization unit | Cloud Control registration status of sub-organization units
|
| Registered Account | Sub Account’s Cloud Control registration status
|
View Account List
Organization Unit and Account Management on the page, when you click the View Account List button, you can view and manage the Account list that constitute Cloud Control.
| Category | Detailed description |
|---|---|
| Account registration | Register the selected Account from the Account list to Cloud Control
|
| Account name | Account name |
| Account ID | Account’s ID |
| Account’s user email | |
| Status | Organization unit or Account’s Cloud Control registration status
|
Organization and Account Detailed Information Check
You can view and edit the detailed information of the organization unit and Account.
To view detailed information, follow the steps below.
- All Services > Management > Cloud Control Click the menu. Navigate to Cloud Control’s Service Home page.
- Service Home page, click the Organization menu. Move to the Organization unit and Account management page.
- Organization Unit and Account Management page’s View Hierarchy button, click it.
- Click the name of the resource whose detailed information you want to view in the hierarchy list. You will be taken to the detailed page of that resource.
- Root: Root Details go to the page. For more details, please refer to Root Details Info.
- Organization unit name: Organization unit details navigate to the page. For more details, see Organization unit detailed information.
- Account name: Account details navigate to the page. For more details, refer to Account detailed information.
Root Detailed Information
Root detail page allows you to view and manage the detailed information of the organization Root and the sub Account list. Root Details page consists of Basic Information, Sub Account tabs.
Basic Information
You can check the basic information about organization Root and the organizational units and account count registered in Cloud Control.
| Category | Detailed description |
|---|---|
| service | service name |
| Resource Type | Service Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name |
| Resource ID | Unique resource ID in the service |
| Creator | User who created the service |
| Creation time | Service creation time |
| Modifier | User who edited the service information |
| Modification Date | Date Service Information Was Modified |
| Registered organization unit | Cloud Control registration status of Root sub-organization units
|
| Registered Account | Root sub Account’s Cloud Control registration status
|
Sub Account
You can view and manage the list of Accounts under Root and the registration status of Cloud Control.
| Category | Detailed description |
|---|---|
| Account registration | Register the selected Account from the Account list to Cloud Control
|
| Account name | Account name |
| Account’s user email | |
| Status | Organization unit or Account’s Cloud Control registration status
|
Organization Unit Detailed Information
Organizational Unit Details page allows you to view and manage detailed information of the organizational unit, sub Accounts, and applied preventive guardrails. Organization Unit Details page consists of Basic Information, Sub Account, Preventive Guardrails tabs.
Basic Information
You can view basic and detailed information about the organization unit.
| Category | Detailed description |
|---|---|
| service | service name |
| Resource Type | Service Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name |
| Resource ID | Unique resource ID in the service |
| Creator | User who created the service |
| Creation time | Service creation time |
| Modifier | User who edited the service information |
| Modification Date/Time | Date and time the service information was modified |
| Organizational unit name | Name of the organizational unit |
| Applied Guardrail | Number of guardrail types applied to the current organization unit |
| Registered organization unit | Current organization unit’s sub-unit Cloud Control registration status
|
| Registered Account | Current organization unit sub Account’s Cloud Control registration status
|
| Higher organization unit | Hierarchy of higher organization units of the current organization unit |
| Re-registration | Re-register the current organization unit to Cloud Contorl
|
Sub Account
You can view and manage the list of sub-accounts of the organization unit.
| Category | Detailed description |
|---|---|
| Account registration | Register the selected Account from the Account list to Cloud Control
|
| Account name | Account name |
| Account’s user email | |
| Status | Organization unit or Account’s Cloud Control registration status
|
Preventive Guardrail
You can view and manage the list of preventive guardrails applied at the organizational unit level.
| Category | Detailed description |
|---|---|
| Target Service Name | Guardrail applicable service name |
| Guardrail Name | Name of the guardrail
|
| Type | Application method |
| Application method | Display of guardrail’s application method
|
| Remove | Remove the selected guardrail from the guardrail list
|
| Apply Preventive Guardrail | New preventive guardrail can be applied at the organizational level
|
Account Check detailed information
Account Details page you can view the detailed information of the Account and the list of applied preventive guardrails. Account Detail page consists of Basic Information, Prevention Guardrail tabs.
Basic Information
You can view basic and detailed information about the organization unit.
| Category | Detailed description |
|---|---|
| service | service name |
| Resource Type | Service Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name |
| Resource ID | Unique resource ID in the service |
| Creator | User who created the service |
| Creation time | Service creation time |
| Editor | User who edited the service information |
| Modification Date | Date Service Information Was Modified |
| Account’s user email | |
| Applied Guardrail | Number of guardrail types applied to the current organization unit |
| ID Center username | ID Center user email |
| Upper organizational unit | Current Account’s upper organization unit hierarchy |
| Register | Current Account’s organization unit can be changed
|
Prevention Guardrail
You can view the list of preventive guardrails applied to the Account.
| Category | Detailed description |
|---|---|
| Target Service Name | Guardrail applicable target service name |
| Guardrail Name | Name of the guardrail
|
| Type | Application Method |
| Application method | Display of the guardrail’s application method
|
Access Portal Check access information
User and Access page you can check the Access Portal connection URL and the password required for connection.
Access Portal to check the connection information, follow the steps below.
- All Services > Management > Cloud Control Click the menu. Navigate to Cloud Control’s Service Home page.
- Service Home page, click the User and Access menu. Navigate to the User and Access page.
- User and Access page’s Integrated Access Management area, check the information.
| Category | Detailed description |
|---|---|
| Password | Password for Access Portal access |
| Access Portal URL | Access Portal access URL
|
| Permission Set | A collection of admin policies used by ID Center to determine the valid permissions of users who can access a specific Account |
If the landing zone is configured with a self‑managed Account access, refer to the following.
- Cloud Control does not automatically create directory groups or permission sets.
- When provisioning an Account via the Account factory or registering an existing Account, the user is automatically assigned.
- You can manage access to the Account via ID Center or other Account access methods.
Check user credential information
On the User and Access page, you can check the user credential source type and ID Center ID.
To verify user credential information, follow the steps below.
- All Services > Management > Cloud Control Please click the menu. Navigate to Cloud Control’s Service Home page.
- Click the User and Access menu on the Service Home page. You will be taken to the User and Access page.
- User and Access page’s User Credential Management area, check the information.
| Category | Detailed description |
|---|---|
| Credential Source | Types of credential sources set in ID Center
|
| ID Center ID | ID Center’s ID
|
| User Group | A group formed to classify workers who perform specific tasks in an organization |
Check shared Account
You can view the shared Account information of Cloud Control.
To check the shared Account information, follow the steps below.
- All Services > Management > Cloud Control Click the menu. Go to the Service Home page of Cloud Control.
- Click the Shared Account menu on the Service Home page. Navigate to the Shared Account page.
- Shared Account page is composed of Management Account, Log Account, Audit Account widgets.
- Each widget displays the Account name, Account ID, and email information, and clicking the widget name navigates to that Account’s detail page.
| Category | Detailed description |
|---|---|
| Management Account | Account that creates new accounts and manages billing and access for all accounts in the organization |
| Log Account | Account used as the repository for API activity and resource configuration logs collected from all Accounts |
| Audit Account | Limited account that allows the security and compliance team to obtain read and write access to all accounts |