Preset Policy

Last updated: 2020-09-09 15:52:32

    Note:

    This document describes the Cloud Access Management (CAM) feature for IM. For more information on CAM for other Tencent Cloud services, see CAM-Enabled Products.

    Essentially, IM CAM binds sub-accounts to policies or grants policies to sub-accounts. You can use preset policies in the console for simple authorization operations. For more information on complicated authorization operations, see Custom Policies.
    The following table describes the preset policies provided by IM.

    PolicyDescription
    QcloudAVCFullAccessIM read and write permissions
    QcloudIMReadOnlyAccessIM read-only permission

    Preset Policy Use Example

    Creating a sub-account with IM permissions

    1. Log in to the User List page in the CAM console with the root account. Then, click Create User.
    2. On the "Create User" page, click Custom Create to go to the "Create Sub-user" page.

      Note:

      For information on the operations that you must perform before configuring user permissions, see Creating a Custom Sub-user.

    3. On the "User Permissions" page:
      (1) Search for and select the Instant Messaging preset policy.
      (2) Click Next.
    4. Click Complete in the "Review" column. After the sub-user is created, record the the login link, download the security credentials, and store them properly. The following table describes the relevant information. o
      InformationSourceFunctionRequired
      Login linkCopied on the pageFacilitate console login and skip the root account entry stepNo
      UsernameSecurity credential CSV fileEntered when you log in to the consoleYes
      PasswordSecurity credential CSV fileEntered when you log in to the consoleYes
      SecretIdSecurity credential CSV fileUsed when a server API is called. For more information, see Access KeyYes
      SecretKeySecurity credential CSV fileUsed when a server API is called. For more information, see Access KeyYes
    5. Provide the authorized party with the preceding login link and security credentials. The authorized party can then use the sub-account to perform IM operations, including accessing the IM console and calling IM server APIs.

    Granting IM permissions to an existing sub-account

    1. Log in to the User List page in the CAM console with the root account. Then, click the sub-account to authorize.
    2. On the "User Details" page, click Add Policy. If the sub-account already has permissions, click Associate Policy.
    3. Select Select policies from the policy list, search for and select the Instant Messaging preset policy, and complete the authorization process as instructed.

    Deleting IM permissions from a sub-account

    1. Log in to theUser List page in the CAM console with the root account. Then, click the sub-account from which you want to delete permissions.
    2. On the "User Details" page, find the Instant Messaging preset policy, and click Unassociate for the policy. Then, complete the deauthorization process as instructed.

    Was this page helpful?

    Was this page helpful?

    • Not at all
    • Not very helpful
    • Somewhat helpful
    • Very helpful
    • Extremely helpful
    Send Feedback
    Help