Set User Privileges

Users need appropriate privileges to access and manage Identity and Access Management (IAM) resources. IAM has a group privilege called Access and manage Identity and Access Management resources, which must be enabled for a group so that the members of this group inherit it through group privilege settings and can access and manage the IAM resources.

Prerequisite: Make sure you have one or more Groups in the User Manager. To create one, see Create a group.

To set user privileges, follow these steps:

1. In the DCD, go to Menu > Management > Users & Groups.

2. Select the Groups tab in the User Manager window.

3. Select the appropriate group to which you want to assign privileges from the list of groups.

4. In the Privileges tab, select Access and manage Identity and Access Management resources.

Set user privileges

Revoke user privileges

To revoke user privileges, follow these steps:

1. In the DCD, go to Menu > Management > Users & Groups.

2. Choose one of the following options:

Option 1: Remove the User from all the Groups in which the Privilege is Enabled

1. Select the user from the Users tab in the User Manager window.

2. Go to the Groups tab, select the group name enabling the privilege, and click Remove from Group.

3. Repeat step 2 for all the groups where the privilege to be revoked is applied.

Remove the user from the Group
Option 2: Remove the Privilege from all the Groups the User Belongs To

1. Select the Groups tab in the User Manager window.

2. Select the Group Name in which the privilege to be revoked is applied and the user belongs to this group.

3. Clear the checkbox against the privilege name.

4. Repeat steps 2 and 3 for all the groups where the privilege to be revoked is applied.

Remove the privilege from all Groups user belongs to

Note: To revoke this privilege from a contract administrator, turn off the administrator option on the user account. After performing this action, the contract administrator will become a contract user, and the privileges set up for the user before becoming an administrator will be in effect.

Last updated

Was this helpful?