首页> 外国专利> Delegated administrator with defined permission boundaries in a permission boundary policy attachment for web services and resources

Delegated administrator with defined permission boundaries in a permission boundary policy attachment for web services and resources

机译:委托管理员具有定义的权限边界,用于Web服务和资源的权限边界策略附件

摘要

A method and system for generating permissions policies and permission boundary policies are described. The system receives a first request from a central administrator to create a delegated administrator, the first request specifying with one or more access permissions. The system generates a permission boundary policy that specifies the one or more access permissions and a first permissions policy that grants permissions to the delegated administrator to at least one of create an IAM principal with the permission boundary policy or attach a second permissions policy to the IAM principal. An effective permission given to the IAM principal is an intersection of access permissions specified in the first permissions policy and the one or more access permissions in the permission boundary policy. The system attaches the first permissions policy and the permission boundary policy to the delegated administrator.
机译:描述了用于生成权限策略和权限边界策略的方法和系统。该系统从中央管理员接收第一请求以创建委派管理员,该管理员具有一个或多个访问权限指定的第一请求。该系统生成权限边界策略,该策略指定一个或多个访问权限和第一权限策略,其授予委派管理员的许可,其中包含权限边界策略或将第二个权限策略附加到IAM中的第二个权限策略主要的。对IAM校长的有效权限是在第一个权限策略中指定的访问权限以及权限边界策略中的一个或多个访问权限。系统将第一个权限策略和权限边界策略附加到委派管理员。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号