Available in Classic and VPC
You can create and manage sub accounts as well as groups and assign policies to sub accounts.
Dashboard interface
In the dashboard, you can change the access-related settings for sub accounts, and check the number of created sub accounts, groups, and policies.

| Item | Description |
|---|---|
| Sub account login page access key | Access key to the sub account login page. You can edit or delete the login page access key at any time. |
| Sub account login address | URL to access the sub account. Sub accounts can only be accessed through this URL. The main account administrator should provide the sub account login page to the sub account users. |
| Set valid session expiration time | Set valid session expiration time for sub accounts. You can choose an expiration time for valid sessions from 10 minutes, 30 minutes, 1 hour, or 3 hours, and if there is no activity during the set time for the sub account, the user will be automatically logged out |
| Set password expiration | Set a forced expiration date for sub account's password. The forced expiration date can be selected from 60, 90, 120, and 180 days, and if the sub account continues to use the same password after the set expiration date, the console can't be used until the password is changed. |
| Disable long-term inactive sub accounts | Configure disabling for sub accounts that have been inactive for a long time. You can select an inactivity period of 90, 180, or 365 days. Sub accounts exceeding the selected inactivity period are automatically diabled. |
| Resources | Check the number of sub accounts, groups, policies, and roles assigned to the account. |
Create sub account
To create sub accounts:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account.
- In the Sub Accounts menu, click [Create Sub Account].
- Enter the sub account information.
- Login ID: ID to use when logging in.
- User name: Name of the user who will use the sub account.
- Email: Your email address.
- Access permission
- Console access: Set the degree of console access permissions for sub accounts.
- Accessible from anywhere: Console access is available without any IP restrictions
- Access restricted to specific IP ranges: You can restrict the IP addresses used to access the console from sub accounts to a specific range. You can register up to 100 IP ranges, including a single IP or subnet.
- API Gateway access: Set whether to allow access to the API gateway. If allowed, the created sub account can manage the access key and use it to access the API Gateway.
- Accessible from all sources: Accessible without any IP or VPC server restrictions.
- Accessible only from specified sources: You can restrict the access sources for sub account API.
- IP: You can register an IP range, including a single IP or subnet.
- VPC: VPC currently in use can be registered.
- VPC Server: You can register a server within the currently used VPC.
- Console access: Set the degree of console access permissions for sub accounts.
- Two-factor authentication settings: Set whether a two-factor authentication method is required for sub accounts
- Memo: Brief description of the sub account.
- Inform password reset: Set to require a password change on first login to the sub account by prompting to visit the password settings page. Not changing the password after initial login directs user to the password settings page for every log in.
- Enter your login password.
- If you need to assign a tag to identify the sub account, specify the tag in the [Tag management] section.
- Click [Create].
- You can create up to 500 sub accounts.
- Sub accounts can manage their own access keys in the console under My Account > Account & Security Management > Security Management > Access Management.
- Two-factor authentication is set when you first log in to the sub account. You can also edit the settings under My Account > Account & Security Management > Security Management > Access Management > Two-factor Authentication Settings in the console.
Apply policies to sub accounts
A policy defines the permissions that the users logged in as sub account can work on.
To apply policies to sub accounts:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Sub Accounts.
- Click on the sub account name to access the sub account details page.
- Click [Add individual permission] in the Policy tab.
- To apply a policy that allows all operations in the sub account, click [Add all permissions].
.png?sv=2026-02-06&spr=https&st=2026-08-04T11%3A45%3A38Z&se=2026-08-04T12%3A06%3A38Z&sr=c&sp=r&sig=LOtEEGSqsIxYDM0P8w6F2qI1LlCNEEYc5caI0emM9mQ%3D)
- To apply a policy that allows all operations in the sub account, click [Add all permissions].
- When the Add policy window appears, select the policy to assign to the account.
- You can select multiple policies.
- You can search for a policy in the search field at the top right corner of the page.
- After selecting the policy to assign to the sub account, click [Add].

- Check if the policy has been successfully added.
- To add a group, click [Add] in the [Group] tab.
- Learn how to create a group in Create group.
Manage sub account
You can edit or delete sub account information, delete multiple sub accounts at once, and suspend or unsuspend them. If you have Sub Account permissions, you can also log in as a sub account and create a new sub account.
Check sub account details
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Sub Accounts.
- Click the login ID.
- Check the details of the sub account.
| Item | Description |
|---|---|
| ID | ID automatically assigned when a sub account is created. |
| NRN | Ncloud Resource Names. Resource name. |
| Creation date and time | Date and time when the sub account was created. |
| Edit date and time | Date and time when the sub account information was last edited. |
| Login ID. | Sub account login ID. |
| User name | Sub account user's name. |
| Status | Sub account status. - In use: Available for login and service use - Suspended: Temporarily suspended. |
| User's email address. | |
| Login password | The login password is not displayed. Click [Change password] to change the password. |
| Number of days using the password | Total cumulative days used without changing the sub account password. This can help with periodic password changes. |
| Two-factor authentication option | Whether two-factor authentication is required when a sub account signs in. - Required: Two-factor authentication is always required at sign-in. - Optional: Two-factor authentication at sign-in can be chosen by sub account. |
| Two-factor authentication usage status | Whether the sub account uses two-factor authentication. |
| Access permission | Console access settings and API access settings. |
| Last log in date and time | Date and time when the sub account last logged in. |
| Number of days using the access key | Number of days of use for the oldest access key. |
| Last Git log in date and time | Date and time when the sub account last signed in to Git in SourceCommit. |
| Last Access Key use date and time | Date and time when the sub account last used an Access Key. |
| Inactivity period | The length of time a sub account has been inactive, based on its access permissions. - Combines the last sign-in time, last Git sign-in time, and last Access Key usage time to show how length of inactivity. |
| Notes | A brief description of the sub account. |
| Tag | Assign tag keys/values to easily categorize sub accounts. - View, create, edit, and delete all tags with [Tag management]. - Only 1 tag value can be assigned to 1 tag. - When adding a tag value to the previously registered tag key, update newly entered tag value. |
- Check the [Policy] tab, [Group] tab, and [Access Key] tab at the bottom of the Details page.
- [Policy]: Assign or withdraw a policy to a sub account.
- [Group]: Add or remove a sub account as a member of a group.
- [Access key]: Enabled only for sub accounts with API Gateway Access included. You can add, delete, use, and suspend Access Key IDs for the use of API gateway.
Edit sub account
To edit sub account information:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Sub Accounts.
- Click the login ID.
- Click [Edit] from the top of the Sub account details page.
- Edit the information and click [Edit].
- The login ID cannot be edited.
Delete sub account
To delete a sub account:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Sub Accounts.
- Click the login ID.
- Click [Delete] from the top of the Sub account details page.
- When the delete window appears, click [Delete].
Disable sub accounts
The suspend feature puts the account in a state in which NAVER Cloud Platform services cannot be used.
To suspend a sub account:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Sub Accounts.
- Click the login ID.
- Click [Disable] from the top of the Sub account details page.
- When the suspend window appears, click [Disable].
- Suspended sub accounts show their Status as Suspended.
Suspended sub accounts have the [Enable] button activated. You can reactivate the status of a suspended sub account by clicking [Enable].
Set access restrictions for sub accounts
To prevent console access from unauthorized locations, you can set it to be available only within specific IP ranges, and you can limit the resources that can be used by sub accounts.
To restrict console access to a specific IP range:
- Access with the sub account's details.
- Click [View/Change allowed IP range] in Access type.
- Select Allow access from specified IP range, enter the IP, and then click [Add].
- Clicking [My IP] automatically adds your current IP range.
- Click [Edit].
To set up an accessible source:
- Access with the sub account's details.
- Click [View/Change accessible source] in the access type field.
- Select Allow access from designated source, and then click [Add].
- Select the resources to grant access.
- IP: You can register an IP range, including a single IP or subnet.
- VPC: VPC currently in use can be registered.
- VPC Server: You can register a server within the currently used VPC.
- Click [Apply].
- Click [Edit].
- If only IP is specified as the accessible source, API access in VPC Server is not allowed.
- When you set VPC as the allowed Source, API access from VPC Servers within the VPC is allowed.
- Object Storage and Archive Storage are not subject to the API access control through the Sub Account service.
Manage groups
You can group frequently used sub accounts together. Create, edit, and delete groups or add/delete sub accounts or policies to a group.
Create groups
To create a group and add sub accounts and policies to the group:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Groups.
- Click [Create groups].
- When the group creation window appears, enter the group name.
- If you need to assign a tag to identify the group, specify the tag in the [Tag management] section.
- Click [Create].
- The group name can be changed.
- Once the group is created, click [Add] in the [Sub Accounts] tab.
- Select the sub account to set as the group and click [Add].
- Click [Add individual permission] in the [Policy] tab.
- Once the add policy window appears, select the policy you want to add to the group and click [Add].
- To grant all permissions at once, click [Add all permissions].
- You can create up to 300 groups.
- The maximum number of groups that can be assigned to each sub account is 10.
View group details
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Groups.
- Click the group name.
- Check group's details.
Item Description ID ID automatically assigned when created. NRN Ncloud Resource Names. Resource name. Creation date and time The date and time of group creation. Edit date and time The date and time when group was edited. Group name Name of the group. Tag Assign tag keys/values to easily distinguish.
- View, create, edit, and delete all tags with [Tag management].
- Only 1 tag value can be assigned to 1 tag.
- When adding a tag value to the previously registered tag key, update the newly entered tag value. - Check the [Sub account] and [Policy] tabs at the bottom of the Details page.
- [Sub account]: Add or remove a sub account to be included in a group.
- [Policy]: Add or remove a policy to be applied to a group.
Edit group name
To edit a group name:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Groups.
- Click
> Edit to the right of the group name to be edited in the group list. - Edit the group name, and then click [Edit].
Delete groups
To delete a group:
- From NAVER Cloud Platform console, navigate to Menu > All Services > Management & Governance > Sub Account > Groups.
- Click
> Delete to the right of the group name to be edited in the group list. - When the delete window appears, click [Delete].
- Deleting a group does not affect the sub accounts and policies that are included in the group.
- In the case of a sub account included in a group, the deleted group is removed from the list in the Details > Group tab of the sub account.