Tenant Cloud
Management and Audit
Cloud Organization
Operation Guide
Multi-account Authorization Overview
On the Multi-account Authorization page, you can configure CAM user synchronization according to the directory structure of your cloud organization.
Identity Center users can access the account's cloud resources through CAM users. Detailed descriptions are as follows:
| Access Method | Note | Synchronization Method |
|---|---|---|
| Configuring CAM User Synchronization | Enterprises manage users accessing the cloud platform in Cloud Organization Identity Center. Through CAM user synchronization, users can log in to member accounts and access the CAM users within those accounts, and then access the cloud resources of the member accounts. | When configuring CAM user synchronization, Identity Center will initiate tasks for each tuple (user-account). After synchronization, the access permissions in CAM are empty and need to be configured in CAM. |
CAM User Synchronization Description
If you need to perform a one-time batch authorization for multiple accounts and multiple identities, you can choose Cloud Organization > Identity Center, go to the Multi-account Permission Management page, view the account directory tree, and perform the following operations:
- Select one or more accounts in the account tree.
- Select one or more Identity Center identities.
- Click Configure CAM User Synchronization. The Identity Center service will complete the authorization for you in batches.
- In batch synchronization, if a duplicate operation is attempted for some existing synchronizations, the operation will fail. However, new synchronizations in the same batch will succeed.
- After successful configuration, a CAM user with the same name as the Identity Center user will be created in the target account.
- Authorization: Access the target account to authorize the CAM user created in the previous step.
CAM users have no permissions by default. You need to grant them permissions on corresponding resources. - Identity Center users access the authorized resources in the target account through the CAM user identity.
For specific operations, see Configuring CAM User Synchronization.
- Authorization: Access the target account to authorize the CAM user created in the previous step.