This document introduces the basic concept of Identity Center.
| Concept | Description |
|---|---|
| Space | To enable Identity Center, you need to create a space. All resources of Identity Center are maintained in this space. For a cloud organization, only one space can be created. The space name will be used in the user login URL. |
| User | User is an identity type in Identity Center. It means that if you enable the Identity Center service of Cloud Organization, before the CAM synchronization operation is performed, the user you created in Identity Center has no feature, identity, or permission such as login or access. You can centrally create and manage users accessing the cloud platform in Identity Center. Users can be granted permissions to access the cloud platform account. |
| User group | User group is an identity type in Identity Center. You can add users to user groups and grant users permissions by user group for unified permission management. |
| SCIM synchronization | Identity Center supports user and user group synchronization based on the SCIM protocol. With SCIM synchronization, you only need to manage identities in your enterprise identity management system, eliminating the need for manual management of users and user groups in Identity Center. This enhances management efficiency and security. |
| Account | Accounts include an admin account and member accounts. - Admin account: The admin account is the super administrator of an enterprise organization. Only the admin account can manage Identity Center. - Member account: A member account cannot manage Identity Center and cannot be viewed. |
| Multi-account authorization | According to the structure of your cloud organization, you can set users or user groups allowed to be accessed by each account, as well as their access permissions. You can authorize the enterprise admin account or any member account. For more information, see Multi-account Authorization Overview. |
| Login portal | The login portal is an independent portal for Identity Center users to log in and use cloud platform resources. After logging in, Identity Center users can view the accounts they have permissions to access and only access the cloud platform console within the scope allowed by the granted permissions. You can view the URL of the login portal on the overview page of Identity Center. For more information, see Identity Center User Login. |
| Identity Center administrator | Identity Center administrators refer to the admin account for which Identity Center is enabled and CAM users with the QcloudOrganizationFullAccess permission under the admin account. |
| Single sign-on (SSO) | Identity Center supports SAML 2.0-based SSO. The cloud platform is the service provider (SP), and an enterprise's own identity management system is the identity provider (IdP). Through SSO, enterprise employees can directly log in to Identity Center with their user identities in the IdP. |