- Print
- PDF
Sub Account permissions management
- Print
- PDF
Available in Classic and VPC
By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Sub Account. Sub Account provides system managed policies and user-defined policies for setting management and administration permissions.
Sub Account is a service provided free of charge upon subscription request. For more information on Sub Account, see Services > Management & Governance > Sub Account on NAVER Cloud Platform portal and the Sub Account user guide.
System-managed policies
System-managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once system-managed policies are granted to a sub account created in Sub Account that sub account can use Sub Account. The following is a brief description of the system-managed policies of Sub Account.
Policy name | Description |
---|---|
NCP_ADMINISTRATOR | Permission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts |
NCP_FINANCE_MANAGER | Permission to view the Manage usage and Manage payment method, and Solution usage status menu on the portal's My Page |
NCP_SUB_ACCOUNT_MANAGER | Permission to use the full Sub Account feature sets including External Access |
NCP_SUB_ACCOUNT_VIEWER | Permission to only use the view list and view features in Sub Account |
NCP_EXTERNAL_ACCESS_MANAGER | Permission to use all the features in External Access |
NCP_EXTERNAL_ACCESS_VIEWER | Permission to only use the view list and search functions in External Access |
User-defined policies
User-defined policies are policies that users may create. Once the user-defined policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description of the user-created policies of Sub Account.
Sub Account
Type | Action name | Related action | Resource type | Group by resource type | Action description | Applicable condition keys |
---|---|---|---|---|---|---|
View | View/getResourceCount | - | - | Dashboard | View Sub Account resource information | - All Principal attribute condition keys |
View | View/getSubAccountList | - | - | SubAccount | View sub account list | - All Principal attribute condition keys |
View | View/getSubAccountDetail | View/getSubAccountList | SubAccount | SubAccount | View sub account details | - All Principal attribute condition keys - ncp: resourceTag |
View | View/getSubAccountAccessKey | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | View sub account's access key | - All Principal attribute condition keys - ncp: resourceTag |
View | View/getGroupList | - | - | Group | View group list | - All Principal attribute condition keys |
View | View/getGroupDetail | View/getGroupList | Group | Group | View group details | - All Principal attribute condition keys - ncp: resourceTag |
View | View/getPolicyList | - | - | Policy | View policy list created by user | - All Principal attribute condition keys |
View | View/getPolicyDetail | View/getPolicyList | Policy | Policy | View details of policy created by user | - All Principal attribute condition keys - ncp: resourceTag |
View | View/validatePolicy | - | - | Policy | View policy validity | - All Principal attribute condition keys |
View | View/getRoleList | - | - | Role | View role list | - All Principal attribute condition keys |
View | View/getRoleDetail | View/getRoleList | Role | Role | View role details | - All Principal attribute condition keys - ncp: resourceTag |
View | View/getServerInstanceList | - | - | Role | View server resource list to be granted a role | - All Principal attribute condition keys |
View | View/getServerInstanceDetail | View/getServerInstanceList | VPCServer:Server | Role | View Server resource details to assign roles | - All Principal attribute condition keys - ncp: resourceTag |
View | View/getStsSessionToken | - | - | STS | Create STS token and view created STS token information | - All Principal attribute condition keys |
Change | Change/manageLoginPageSetting | - | - | Dashboard | Manage access page settings | - All Principal attribute condition keys |
Change | Change/managePasswordSetting | - | - | Dashboard | Manage password settings | - All Principal attribute condition keys |
Change | Change/manageSessionSetting | - | - | Dashboard | Manage session expiration settings | - All Principal attribute condition keys |
Change | Change/createSubAccount | View/getSubAccountList | - | SubAccount | Create sub account | - All Principal attribute condition keys |
Change | Change/updateSubAccount | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | Edit sub account | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/deleteSubAccount | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | Delete sub account | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/suspendSubAccount | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | Temporarily suspend and disconnect sub account | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/resetSubAccountPassword | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | Reset sub account password | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/addPolicyToSubAccount | View/getSubAccountDetail View/getSubAccountList View/getPolicyList View/getPolicyDetail | SubAccount | SubAccount | Assign policy to sub account | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/removePolicyFromSubAccount | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | Delete policy from sub account | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/createSubAccountAccessKey | View/getSubAccountDetail View/getSubAccountList View/getSubAccountAccessKey | SubAccount | SubAccount | Create sub account's Access Key | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/deleteSubAccountAccessKey | View/getSubAccountDetail View/getSubAccountList View/getSubAccountAccessKey | SubAccount | SubAccount | Delete sub account's Access Key | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/manageSubAccountAccessKeyState | View/getSubAccountDetail View/getSubAccountList View/getSubAccountAccessKey | SubAccount | SubAccount | Manage sub account access key status | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/manageSubAccountAllowSourceSetting | View/getSubAccountDetail View/getSubAccountList | SubAccount | SubAccount | View and edit the Source IP or VPC Server that can access the console or API | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/resetSubAccountMFA | getSubAccountList getSubAccountDetail | SubAccount | SubAccount | Reset sub account's two-factor authentication settings | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/addSubAccountToGroup | View/getGroupList View/getSubAccountDetail View/getSubAccountList View/getGroupDetail | Group SubAccount | Group SubAccount | Add sub accounts to group | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/removeSubAccountFromGroup | View/getGroupList View/getSubAccountDetail View/getSubAccountList View/getGroupDetail | Group SubAccount | Group SubAccount | Delete sub account from group | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/addPolicyToGroup | View/getGroupList View/getPolicyList View/getPolicyDetail View/getGroupDetail | Group | Group | Assign policy to group | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/removePolicyFromGroup | View/getGroupList View/getGroupDetail | Group | Group | Delete policy from group | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/createGroup | View/getGroupList | - | Group | Create groups | - All Principal attribute condition keys |
Change | Change/updateGroup | View/getGroupList View/getGroupDetail | Group | Group | Edit group information | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/deleteGroup | View/getGroupList View/getGroupDetail | Group | Group | Delete groups | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/createPolicy | View/getPolicyList | - | Policy | Create new policy | - All Principal attribute condition keys |
Change | Change/updatePolicy | View/getPolicyList View/getPolicyDetail | Policy | Policy | Change policy created by user | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/deletePolicy | View/getPolicyList View/getPolicyDetail | Policy | Policy | Delete policy created by user | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/createRole | View/getRoleList | - | Role | Create role | - All Principal attribute condition keys |
Change | Change/updateRole | View/getRoleDetail View/getRoleList | Role | Role | Edit role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/deleteRole | View/getRoleDetail View/getRoleList | Role | Role | Delete role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/addPolicyToRole | View/getPolicyList View/getRoleDetail View/getRoleList View/getPolicyDetail | Role | Role | Assign policy to role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/removePolicyFromRole | View/getRoleDetail View/getRoleList | Role | Role | Delete policy from role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/attachRoleToServer | View/getRoleDetail View/getServerInstanceList View/getRoleList View/getServerInstanceDetail | Role | Role | Assign role to Server resource | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/detachRoleFromServer | View/getRoleDetail View/getRoleList | Role | Role | Remove roles from Server resource | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/suspendRole | View/getRoleDetail View/getRoleList | Role | Role | Suspend and release Roles | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/attachRoleToAccount | View/getRoleDetail View/getRoleList | Role | Role | Set target accounts in Account Role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/detachRoleFromAccount | View/getRoleDetail View/getRoleList | Role | Role | Delete target accounts in Account Role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/switchRole | - | Role | Role | Switch permissions to the assigned Account Role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/tagSubAccount | View/getSubAccountList View/getSubAccountDetail | SubAccount | SubAccount | Assign tag to subaccount | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/untagSubAccount | View/getSubAccountList View/getSubAccountDetail | SubAccount | SubAccount | Delete tag from sub account | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/tagGroup | View/getGroupList View/getGroupDetail | Group | Group | Assign tag to group | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/untagGroup | View/getGroupList View/getGroupDetail | Group | Group | Delete tag from group | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/tagPolicy | View/getPolicyList View/getPolicyDetail | Policy | Policy | Assign tag to Policy | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/untagPolicy | View/getPolicyList View/getPolicyDetail | Policy | Policy | Delete tag from Policy | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/tagRole | View/getRoleList View/getRoleDetail | Role | Role | Assign tag to role | - All Principal attribute condition keys - ncp: resourceTag |
Change | Change/untagRole | View/getRoleList getRoleDetail | Role | Role | Delete tag from role | - All Principal attribute condition keys - ncp: resourceTag |
External Access
Type | Action name | Related action | Resource type | Group by resource type | Action description | Available Condition keys |
---|---|---|---|---|---|---|
Change | Change/createTrustAnchor | getCAList getCADetail | \- | TrustAnchor | Create TrustAnchor | - All Principal attribute condition keys |
Change | Change/createProfile | getRoleList getRoleDetail | \- | Profile | Create Profile | - All Principal attribute condition keys |
Change | Change/deleteTrustAnchor | getTrustAnchorList getTrustAnchorDetail | TrustAnchor | TrustAnchor | Delete TrustAnchor | - All Principal attribute condition keys |
Change | Change/disableTrustAnchor | getTrustAnchorList getTrustAnchorDetail | TrustAnchor | TrustAnchor | Disable TrustAnchor | - All Principal attribute condition keys |
Change | Change/enableTrustAnchor | getTrustAnchorList getTrustAnchorDetail | TrustAnchor | TrustAnchor | Enable TrustAnchor | - All Principal attribute condition keys |
View | View/getTrustAnchorList | \- | \- | TrustAnchor | View list of TrustAnchor | - All Principal attribute condition keys |
View | View/getTrustAnchorDetail | getTrustAnchorList | TrustAnchor | TrustAnchor | View TrustAnchor details | - All Principal attribute condition keys |
Change | Change/updateTrustAnchor | getTrustAnchorList getTrustAnchorDetail getCAList getCADetail | TrustAnchor | TrustAnchor | Edit TrustAnchor | - All Principal attribute condition keys |
Change | Change/deleteProfile | getProfileList getProfileDetail | Profile | Profile | Delete Profile | - All Principal attribute condition keys |
Change | Change/disableProfile | getProfileList getProfileDetail | Profile | Profile | Disable Profile | - All Principal attribute condition keys |
Change | Change/enableProfile | getProfileList getProfileDetail | Profile | Profile | Enable Profile | - All Principal attribute condition keys |
View | View/getProfileList | \- | \- | Profile | View list of Profile | - All Principal attribute condition keys |
View | View/getProfileDetail | getProfileList | Profile | Profile | View Profile details | - All Principal attribute condition keys |
Change | Change/updateProfile | getProfileList getProfileDetail getRoleList getRoleDetail | Profile | Profile | Edit Profile | - All Principal attribute condition keys |
View | View/getSubjectList | \- | \- | Subject | View SubjectActivity list | - All Principal attribute condition keys |
View | View/getSubjectDetail | getSubjectList | Subject | Subject | View SubjectActivity details | - All Principal attribute condition keys |
View | View/getCAList | \- | \- | TrustAnchor | View CA list | - All Principal attribute condition keys |
View | View/getCADetail | getCAList | Private CA:CA | TrustAnchor | View CA details | - All Principal attribute condition keys |
View | View/getRoleList | \- | \- | Profile | View role list | - All Principal attribute condition keys |
View | View/getRoleDetail | getRoleList | Sub Account:Role | Profile | View role details | - All Principal attribute condition keys |
Change | Change/importCrl | getTrustAnchorDetail | Crl | Crl | Import Crl | - All Principal attribute condition keys |
Change | Change/deleteCrl | getTrustAnchorDetail getCrlDetail getCrlList | Crl | Crl | Delete Crl | - All Principal attribute condition keys |
Change | Change/disbleCrl | getTrustAnchorDetail getCrlDetail | Crl | Crl | Disable Crl | - All Principal attribute condition keys |
Change | Change/enableCrl | getTrustAnchorDetail getCrlDetail | Crl | Crl | Enable Crl | - All Principal attribute condition keys |
View | View/getCrlDetail | getTrustAnchorDetail getCrlList | Crl | Crl | View Crl details | - All Principal attribute condition keys |
View | View/getCrlList | getTrustAnchorDetail | Crl | Crl | View Crl list | - All Principal attribute condition keys |
Even when you are granted permission for a specific action, if you are not also granted permissions for the related actions that are required, you will not be able to perform tasks properly. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and will not forcibly include them. Therefore, use caution when setting permissions.