Associating/Unassociating Policy with/from User Group

Last updated: 2021-08-04 16:00:20

    Overview

    After creating and authorizing a user group, you can associate/unassociate policies with/from it to quickly change its permissions. Sub-accounts in the user group can manage the resources under the root account within the scope of the granted permissions.

    • When a policy is associated with a user group, all users in it will have the permissions of the policy.
    • When a policy is unassociated from a user group, all users in it will no longer have the permissions of the policy.

    Prerequisites

    There is an existing user group (if not, please create one).

    Directions

    Associating policy with user group

    1. Log in to the CAM console and enter the User Group page.

    2. Find the target user group and click its name to enter the user group details page.

    3. In the Permissions module on the user group details page, click Associate Policy.

    4. Select one or more policies to be associated in the pop-up window and click OK to associate the policies with the user group.

    Unassociating policy from user group

    1. Log in to the CAM console and enter the User Group page.

    2. Find the target user group and click its name to enter the user group details page.

    3. In the Permissions module on the user group details page, find the policy to be unassociated and click Unassociate on the right.

    4. Click OK to unassociate the policy from the user group.