ID Center Permission Set Management
You can check and manage the set of permissions for the ID Center.
Create a set of permissions
You can create a set of permissions and add it to the ID Center.
To create a set of permissions, follow these steps.
- All services > Management > ID Center menu is clicked. It moves to the Service Home page of ID Center.
- On the Service Home page, click the Authority set menu. It moves to the Authority Set List page.
- On the Authority Set List page, click the Create Authority Set button. It moves to the Create Authority Set page.
- On the Create Permission Set page, in the Enter Basic Information section, enter the basic information and then click the Next button.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Permission Set Name | Required | Enter the name of the permission set
|
| Enter a description of the permission set within 1,000 characters | ||
| Maximum Session Duration | Required | Enter the session time allowed for the user when accessing the Console through the Access Portal
|
- In the 권한 세트 설정 area, select a policy to use and set the policy, then click the 다음 button.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Default Policy | Optional | Connects the default policy provided by Samsung Cloud Platform Console
|
| Custom Policy | Optional | Link the custom policy created under the Account
|
| Inline Policy | Optional | Set the policy to be applied to the permission set directly
|
- In the 입력 정보 확인 area, check the basic information and permission policies of the permission set, and then click the 완료 button.
- When the popup window for creating a set of permissions opens, click the Confirm button.
Check details of permission set
You can check and manage detailed information about the permission set, user group, and account information.
To view detailed information about a set of permissions, follow these steps.
- Click all services > Management > ID Center menu. It moves to the Service Home page of ID Center.
- On the Service Home page, click the 권한 세트 menu. It moves to the 권한 세트 목록 page.
- On the Authority Set List page, click the authority set to view detailed information. It moves to the Authority Set Details page.
- Authority Set Details page displays basic information and consists of Basic Information, Authority, Account tabs.
Basic Information
You can check and modify the basic information of the permission set.
| Classification | Detailed Description |
|---|---|
| Permission Set Delete | Button to delete the permission set |
| Service | Service Name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name
|
| Resource ID | Unique Resource ID |
| Creator | User who created the service |
| Creation Time | Time when the service was created |
| Modifier | User who modified the service information |
| Modified Time | Time when service information was modified |
| Permission Set Name | Policy Name |
| Maximum session persistence time | The session time allowed for users when accessing the Console through the Access Portal
|
| Description | Description of policy name
|
Authority
You can view and manage policies attached to a set of permissions.
| Classification | Detailed Description |
|---|---|
| Default Policy | The default policy linked to the set of permissions
|
| User-defined policy | User-defined policies linked to the authority set
|
| Inline Policy | Service name of inline policy connected to the authority set
|
Account
You can check and modify the account information of the authority set.
| Classification | Detailed Description |
|---|---|
| Account name | Account Name |
| Account ID | Account ID |
| Account’s Email |
Connect Basic Policy
You can attach a new default policy to the set of permissions.
To link a basic policy, follow these procedures.
- Click on 모든 서비스 > Management > ID Center menu. It moves to the Service Home page of ID Center.
- On the Service Home page, click the 권한 세트 menu. It moves to the 권한 세트 목록 page.
- On the Authority Set List page, click the authority set to link to the basic policy. It moves to the Authority Set Details page.
- Authority Set Details page, click the Authority tab.
- Click the Policy Link button in the Basic Policy area. It moves to the Basic Policy Link page.
- On the Basic Policy Linkage page, select the policy you want to link from the list of basic policies, and then click the Complete button.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Connected Base Policy | - | Name of the base policy connected to the authority set |
| Default Policy Link | Required | Select the default policy to link to the authority set
|
- When the policy connection notification popup window opens, click the Confirm button.
Connect custom policies
You can attach a new custom policy to a set of permissions.
To link a custom policy, follow these steps.
- Click all services > Management > ID Center menu. It moves to the Service Home page of ID Center.
- On the Service Home page, click the Authority Set menu. It moves to the Authority Set page.
- On the Authority Set List page, click the authority set to which you want to attach a custom policy. It moves to the Authority Set Details page.
- Authority Set Details page, click the Authority tab.
- Click the Policy Link button in the Custom Policy area. It moves to the Custom Policy Link page.
- Custom Policy Connection page, select the policy you want to connect from the list of custom policies, and then click the Complete button.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Connected User-Defined Policy | - | Default Policy Name Connected to the Authority Set |
| User-defined policy linking | Required | Enter the user-defined policy to be linked to the permission set directly
|
- When the policy connection notification popup window opens, click the Confirm button.
Creating an inline policy
You can modify the inline policies attached to a set of permissions.
To modify the in-line policy, follow the next procedure.
- Click all services > Management > ID Center menu. It moves to the Service Home page of ID Center.
- On the Service Home page, click the Authority Set menu. It moves to the Authority Set List page.
- On the Authority Set List page, click the authority set you want to modify the in-line policy for. It moves to the Authority Set Details page.
- Authority Set Details page, click the Authority tab.
- In the 인라인 정책 area, click the 정책 생성 button. This will take you to the 인라인 정책 생성 page.
- On the 인라인 정책 생성 page, in the 권한 설정 section, select the policy setting method and the service to apply, then click the 다음 button.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Basic Mode/JSON Mode | Required | Select the policy setting method
|
| Service | Required | Select the service to set the policy
|
In policy settings, we provide default mode and JSON mode.
- When entering JSON mode or moving the screen after writing in basic mode, services with duplicated control requirements are integrated into one, and services with incomplete settings are deleted.
- JSON mode where the contents written in does not match the JSON format can not be converted to default mode.
- After setting the permissions, click the Next button.
- To register individual resources as applied resources, please refer to Registering individual resources as applied resources and proceed.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Control Type | Required | Policy Control Type Selection
|
| Action | Required | Select actions provided by each service
|
| Applied Resource | Required | Resource to which the action is applied
|
| Authentication Type | Required | Authentication method for the target users to apply the policy
|
| Applied IP | Required | IP that allows policy application
|
| Additional Conditions | Optional | Add conditions for Attribute-Based Access Control (ABAC)
|
- Check Input Information page, check the entered information and click the Complete button.
- If the policy modification notification popup window opens, click the Confirm button.
Registering individual resources as applied resources
You can register individual resources as applied resources when setting permissions.
To register individual resources as applied resources, follow the next procedure.
- Select an action where individual resources can be selected from the action options.
- Actions that allow individual resource selection are displayed in purple.
- Applied Resource에서 Individual Resource을 클릭하세요.
- Click the Add Resource button. The Add Resource popup window will open.
| Classification | Necessity | Detailed Description |
|---|---|---|
| Free Type | Required | Select the type of resource to add |
| SRN | - | Unique resource ID in Samsung Cloud Platform
|
| Account | Required | Account ID setting
|
| Region | Select | Directly enter the region information of the resource within 100 characters
|
| Resource ID | Required | Directly enter the resource ID to be added within 100 characters
|
Delete permission set
To delete a set of permissions, follow these steps.
- All services > Management > ID Center menu is clicked. It moves to the Service Home page of ID Center.
- On the Service Home page, click the 권한 세트 menu. It moves to the 권한 세트 목록 page.
- Select one or more authorization sets to delete from the authorization set list.
- After confirming the selected set of permissions, click the Delete button. You can also delete them individually from the Delete permission set’s Permission set details page.
- When the popup window notifying the deletion of the permission set opens, click the Confirm button.