# Manage User Account in IAM Federation

Once the organization IDP is onboarded to use IAM Federation, the organization's users can link their accounts to IAM Federation and unlink them whenever needed.

## Link User Account to IAM Federation

Upon linking a user account from the organization to IAM Federation, users can log in to the DCD using their organization credentials.

{% hint style="info" %}
**Prerequisites:**

* The onboarding of the organization IDP must be successfully completed using the discovery endpoint. For more information, see [<mark style="color:blue;">Configure IAM Federation</mark>](https://docs.ionos.com/sections-test/guides/set-up-ionos-cloud/management/identity-access-management/iam-federation/how-tos/configure-iam-federation).
* The user must already have an IONOS Cloud account.
* The logged-in user's email address and the [<mark style="color:blue;">domain linked to the IDP</mark>](https://docs.ionos.com/sections-test/guides/set-up-ionos-cloud/management/identity-access-management/iam-federation/configure-iam-federation#request-domain-ownership) must match.
  {% endhint %}

To link a user's account from the organization to IONOS Cloud DCD, follow these steps:

{% stepper %}
{% step %}

#### Initiate Account Linking

1\. Log in to the DCD using your IONOS Cloud account **Email** and **Password**. For more information, see [<mark style="color:blue;">Log in to the Data Center Designer</mark>](https://docs.ionos.com/sections-test/guides/set-up-ionos-cloud/get-started/log-in-dcd).

2\. Go to **Menu** > **Management** > **IAM Federation**.
{% endstep %}

{% step %}

#### IDP Selection

{% hint style="info" %}
**Note:** Only IDPs onboarded by your organization for IAM Federation and matching your login email domain appear for account linking.
{% endhint %}

* In the **Managed Linked Accounts**, select **Link** under **ACTIONS** against the organization IDP user account that needs to be linked with IAM Federation.

![Link the user account](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-14a6bc515d9b5c13884a6697cae10de2ed3a6cf8%2Fiam-federation-link-user-account.png?alt=media)
{% endstep %}

{% step %}

#### IDP Authentication

{% hint style="info" %}
**Note:** You are logged out of the DCD and redirected to your organization IDP to complete the authentication.
{% endhint %}

* Enter your organization login credentials such as **Email**, **Password**, and **Sign In**.

![User signs in on the organization page](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-e3ea17d68f95256839d86aad268f91a30c3632f2%2Fiam-federation-sign-in-user-organization.png?alt=media)
{% endstep %}

{% step %}

#### Authorization from IDP

* The IDP authenticates the user and authorizes the IONOS Cloud IAM Federation system to access their account information.
  {% endstep %}
  {% endstepper %}

{% hint style="success" %}
**Result:**

* Your organization's user account is successfully linked with IAM Federation.
* The user successfully signs into the DCD and is redirected to the **Manage Linked Accounts**.
  {% endhint %}

![Link user account](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-65146e3cd81f9020b94aa8e2465ff8bb71ad0b3f%2Fiam-federation-user-account-linked.png?alt=media)

## Next steps

User can now log in to the [<mark style="color:blue;">DCD</mark>](https://dcd.ionos.com) using their organization IDP credentials. To do so, see [<mark style="color:blue;">Log in to the Data Center Designer with your Identity Provider</mark>](https://dcd.ionos.com).

## Unlink the user account from IAM Federation

{% hint style="warning" %}
**Warning:** Upon unlinking the user account from IAM Federation, users can log in to the DCD only using their IONOS Cloud account credentials.
{% endhint %}

To unlink a user's account from the organization with IONOS Cloud DCD, follow these steps:

1\. In the **DCD**, go to **Menu** > **Management** > **IAM Federation**.

2\. In the **Managed Linked Accounts**, select **Unlink** under **ACTIONS** against the organization IDP user account that needs to be linked with IAM Federation.

![Unlink the user account](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-7a9ce253baca898bf29b5fca2a3ebb5c2a29d304%2Fiam-federation-unlink-user-account.png?alt=media)

{% hint style="success" %}
**Result:** Your user account from the organization has been successfully unlinked from IAM Federation. From then on, you can log in to the DCD only using your IONOS Cloud account credentials.
{% endhint %}

{% hint style="info" %}
**Note:** User can also unlink their account from the IDP anytime by revoking access to their account information.
{% endhint %}
