Creating a User and Granting Permissions

Use IAM to implement fine-grained permissions control over your VPCEP resources. With IAM, you can:

  • Create IAM users for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing VPCEP resources.

  • Grant users only the permissions required to perform a given task based on their job responsibilities.

  • Entrust an account or a cloud service to perform efficient O&M on your VPCEP resources.

If your account meets your permissions requirements, you can skip this section.

Figure 1 shows the process flow of granting permissions.

Prerequisites

Before granting permissions to user groups, learn about permissions (see Permissions) supported by VPCEP and choose policies or roles according to your requirements. To grant permissions for other services, learn about all Permissions supported by IAM.

Process Flow

**Figure 1** Process of granting VPCEP permissions

Figure 1 Process of granting VPCEP permissions

  1. Create a user group and assign it permissions.

    On the IAM console, create a user group and assign the VPCEndpoint Administrator permissions to the group.

  2. Create an IAM user and add it to the created user group.

  3. Log in as the IAM user and verify permissions.

    In the authorized region, perform the following operations:

    • Click Service List> VPC Endpoint. Then click Create VPC Endpoint in the upper right corner. If you can create a VPC endpoint, the VPCEndpoint Administrator policy is in effect.

    • Choose another service from Service List. If a message appears indicating that you have insufficient permissions to access the service, the VPCEndpoint Administrator policy is in effect.