Overview
This document describes how to associate/disassociate a policy with/from a sub-user. The sub-user can manage the resources under the root account within the scope of the granted permissions.
Directions
Associating a policy with a sub-user
Direct association
You can directly associate a policy with a user to give them the permissions included in the policy.
1. Log in to the CAM Console and enter User List. 2. On the User List page, select the sub-user for which you want to set permissions.
3. Click Authorize in the "Operation" column on the right.
4. In the "Authorize" window that pops up, select one or more policies to be associated.
5. Click OK to associate the policies with the sub-user.
Association via group
You can add a user to a user group to automatically grant the user permissions included in the policies that are associated with the user group. The policy types obtained by the user in this method depend on the policies associated with the user group. If you need to disassociate the user from a policy that is associated with the user group, you must remove the user from the user group.
1. Log in to the CAM Console and enter User List. 2. On the User List page, select the sub-user for which you want to set permissions.
3. Click More Actions > Add to Group in the "Operation" column on the right.
4. Select one or more user groups you want to add the sub-user to.
5. Click OK to add the sub-user to the user groups and associate the sub-user with the group-associated policies.
Disassociating a sub-user from a policy
Direct disassociation
You can directly disassociate a user from a policy to remove the permissions granted.
1. Log in to the CAM Console and enter User List. 2. On the User List page, find the sub-user whose associated policies you want to remove.
3. Click the sub-user name to go to the User Details page.
4. Go to Permissions and locate the policy.
5. On the Permissions tab, find the policy you want to disassociate.
6. Click Unbind in the operation column on the right. In the pop-up window, click OK to detach associated policies for sub-users.
Removing a user from a group
You can remove a user from a user group to automatically disassociate the user from the permissions associated with the group.
1. Log in to the CAM Console and enter User List. 2. On the User List page, find the sub-user whose associated policies you want to remove.
3. Click the sub-user name to go to the User Details page.
4. Go to Groups and locate the policy to be disassociated from.
5. On the user group tab, find the policy you want to disassociate.
6. Click Remove from the Group in the operation column on the right. In the pop-up window, click OK to detach the sub-user policy from the group.