Managing Ncloud Single Sign-On permissions
    • PDF

    Managing Ncloud Single Sign-On permissions

    • PDF

    Article Summary

    Available in Classic and VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Ncloud Single Sign-On. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.

    Note

    Sub Account is a free service provided upon subscription request without additional charge. For more details about Sub Account, see Service > Management & Governance > Sub Account menu in NAVER Cloud Platform portal, as well as the Sub Account User Guide.

    System-managed policies

    System-managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once system-managed policies are granted to a sub account created in Sub Account, that sub account can use Ncloud Single Sign-On. The following is a brief description of the system-managed policies of Ncloud Single Sign-On.

    Policy namePolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My page > Manage notifications in the portal
    NCP_SINGLE_SIGN_ON_MANAGERPermission to use all features of Ncloud Single Sign-On
    NCP_SINGLE_SIGN_ON_VIEWERPermission to only use the View list and Search features in Ncloud Single Sign-On

    User-defined policies

    User-defined policies are policies that users may create. Once the user-defined policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description of the user-created policies of Ncloud Single Sign-On.

    ClassificationAction nameRelated action(s)Resource typeGroupAction description
    Viewview/getApplicationList--ApplicationCheck the application list
    Viewview/getApplicationDetailview/getApplicationListApplicationApplicationCheck application details
    Viewview/accessApplication-ApplicationApplicationLog into application with Sub Account
    Changechange/createApplication--ApplicationCreate a new application
    Changechange/updateApplicationview/getApplicationList
    view/getApplicationDetail
    ApplicationApplicationEdit registered applications
    Changechange/deleteApplicationview/getApplicationList
    view/getApplicationDetail
    ApplicationApplicationDeletes registered applications
    Viewview/getConsentStatus--Consent StatusCheck the consent list
    Changechange/createTenant--TenantCreate tenants
    Changechange/updateTenant-TenantTenantEdit a tenant
    Changechange/deleteTenant-TenantTenantDelete a tenant
    Changechange/updateOrganizationEnable-TenantTenantChange whether to integrate with Organization
    Changechange/manageExternalIDP-TenantTenantChange the status of the external IdP
    Changechange/updateLoginSetting-TenantTenantEdit login settings
    Viewview/getAttributeMapper-TenantTenantCheck user profile settings
    Changechange/updateAttributeMapper-TenantTenantEdit user profile settings
    Viewview/getUserList--UserView user list
    Viewview/getUserDetailview/getUserListUserUserView user details
    Changechange/createUserview/getUserList
    view/getUserDetail
    -UserCreate users
    Changechange/updateUserview/getUserList
    view/getUserDetail
    UserUserEdit user information
    Changechange/deleteUserview/getUserList
    view/getUserDetail
    UserUserDelete users
    Changechange/changeUserStatusview/getUserList
    view/getUserDetail
    UserUserChange user status
    Changechange/addUserToGroupview/getUserList
    view/getUserDetail
    view/getGroupList
    view/getGroupDetail
    change/updateUser
    UserUserAssign users to the group
    Changechange/removeUserFromGroupview/getUserList
    view/getUserDetail
    view/getGroupList
    view/getGroupDetail
    change/updateUser
    UserUserRemove users from the group
    Changechange/manageUserAllowSourceSettingview/getUserList
    view/getUserDetail
    change/updateUser
    UserUserCheck and change the source IP that can access the console or API
    Changechange/expireActiveSessionview/getUserList
    view/getUserDetail
    change/updateUser
    UserUserRemove active sessions of the user
    Changechange/removeUserFromAssignmentview/getUserList
    view/getUserDetail
    change/updateUser
    view/getAssignmentList
    view/getAssignmentDetail
    UserUserRemove users from Assignment
    Viewview/getGroupList--GroupView the group list
    Viewview/getGroupDetailview/getGroupListGroupGroupView group details
    Changechange/createGroupview/getGroupList
    view/getGroupDetail
    -GroupCreate a group
    Changechange/updateGroupview/getGroupList
    view/getGroupDetail
    GroupGroupEdit group information
    Changechange/deleteGroupview/getGroupList
    view/getGroupDetail
    GroupGroupDelete a group
    Changechange/addUserToGroupview/getUserList
    view/getUserDetail
    view/getGroupList
    view/getGroupDetail
    change/updateGroup
    GroupGroupAssign users to the group
    Changechange/removeUserFromGroupview/getUserList
    view/getUserDetail
    view/getGroupList
    view/getGroupDetail
    change/updateGroup
    GroupGroupRemove users from the group
    Changechange/removeGroupFromAssignmentview/getGroupList
    view/getGroupDetail
    change/updateGroup
    view/getAssignmentList
    view/getAssignmentDetail
    GroupGroupRemove Assignment from the group
    Viewview/getPermissionSetList--Permission SetView the Permission Set list
    Viewview/getPermissionSetDetailview/getPermissionSetListPermission SetPermission SetView Permission Set details
    Changechange/createPermissionSetview/getPermissionSetList
    view/getPermissionSetDetail
    -Permission SetCreate Permission Set
    Changechange/updatePermissionSetview/getPermissionSetList
    view/getPermissionSetDetail
    Permission SetPermission SetEdit Permission Set
    Changechange/deletePermissionSetview/getPermissionSetList
    view/getPermissionSetDetail
    Permission SetPermission SetDelete Permission Set
    Changechange/removePermissionSetPolicyview/getPermissionSetList
    view/getPermissionSetDetail
    change/updatePermissionSet
    Permission SetPermission SetRemove managed and user-defined policies assigned to a Permission Set
    Viewview/getAssignmentList--AssignmentView the assignment list
    Viewview/getAssignmentDetailview/getAssignmentListAssignmentAssignmentView Assignment details
    Changechange/createAssignmentview/getAssignmentList
    view/getAssignmentDetail
    -AssignmentCreate Assignment
    Changechange/updateAssignmentview/getAssignmentList
    view/getAssignmentDetail
    AssignmentAssignmentEdit Assignment
    Changechange/deleteAssignmentview/getAssignmentList
    view/getAssignmentDetail
    AssignmentAssignmentDelete Assignment
    Changechange/changeStatusAssignmentview/getAssignmentList
    view/getAAssignmentDetail
    AssignmentAssignmentChange assignment status
    Changechange/assignTargetToAssignmentView/getAssignmentList
    View/getAssignmentDetail
    Change/updateAssignment
    View/getUserList
    View/getUserDetail
    View/getGroupList
    View/getGroupDetail
    View/getIPACLList
    View/getIPACLDetail
    AssignmentAssignmentAssign a user/group and IP ACL to an assignment
    Changechange/removeTargetFromAssignmentView/getAssignmentList
    View/getAssignmentDetail
    Change/updateAssignment
    View/getUserList
    View/getUserDetail
    View/getGroupList
    View/getGroupDetail
    View/getIPACLList
    View/getIPACLDetail
    AssignmentAssignmentRemove a user/group and IP ACL from an assignment
    ChangeChange/createIPACLView/getIPACLList
    View/getIPACLDetail
    IP ACLIP ACLCreate IP ACL.
    ChangeChange/updateIPACLView/getIPACLList
    View/getIPACLDetail
    IP ACLIP ACLEdit an IP ACL.
    ChangeChange/deleteIPACLView/getIPACLList
    View/getIPACLDetail
    IP ACLIP ACLDelete an IP ACL.
    ViewView/getIPACLList--IP ACLView the IP ACL list.
    ViewView/getIPACLDetailView/getIPACLListIP ACLIP ACLView IP ACL details.
    Caution

    Even when you are granted permission for a specific action, you won't be able to perform the task properly unless you are also granted permission for the required related actions. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and won't forcibly include them. Use care when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.