tencent cloud

User Permissions Management

Download
Focus Mode
Font Size
Last updated: 2026-09-08 20:44:42
AI-Translated & Reviewed

How to Import a Third-Party User Source?

iOA supports multiple user sources, including Windows AD, SCIM 2.0, WeCom (Government)/WeCom (On-Premises).
Example: To import a third-party user source, you can refer to iOA SaaS WeCom Integration - Identity Source Configuration or contact technical support, and then click Sync Organizational Structure on the Quick Start page, or click Add New Organizational Structure on the Organizational Structure Management page.


What Is a Self-Managed Account Directory?

On the Organizational Structure Management page, click Add New Organizational Structure and select to create a custom organizational structure. Users must be added to this directory manually. For details, see iOA SaaS Local Self-Built Accounts.


Does Terminal Security Edition Require Importing a User Source?

The terminal security edition does not require importing a user source. You can manage terminals and distribute security policies by using the terminal tree (terminal directory structure) dimension in the terminal list.
If your enterprise is accustomed to managing terminal security policies by user dimension, for example, it has always used AD domain control for security policy configuration management, we recommend importing an identity source.
1. On the Organizational Structure Management page, click Add New Organizational Structure to import an enterprise identity source.

2. On the Terminal Information page, click

and select Add Group.

3. Edit the group information. After the configuration is complete, click OK.
Parameter Name
Description
Group name
Custom name, which is the name of the group to which each terminal belongs.
Parent group
Select the parent group of the terminal from the drop-down list. The default value is all terminals. You can select an existing terminal group as the parent organization of the current group.
Enable group rules
Disabled: Terminals are not automatically grouped. (Select Disabled here)
Enabled: Terminal tree grouping supports setting grouping rules based on local IP address, terminal name, and terminal remarks. Terminal devices are automatically assigned to the corresponding specified groups based on these grouping rules.

4. On the Terminal Information page, select an existing group, click

, and select Import Account Organizational Structure. After the directory is imported, it will be synchronized with the organizational structure information.


Where to Perform Resource Authorization?

1. On the Trusted Access Management > User-based Authorization or Resource-based Authorization page, select the target directory and click Add Resource Authorization.

2. In the resource authorization window, select the desired resources and click OK.


Why Do I Need to Select a User Directory First When Logging In?

Different directories are isolated from each other. Since users come from different sources, you must select the corresponding directory to correctly match account passwords.
Note:
You only need to select the directory once. After successful login, the system will remember the directory you selected last time.


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback