tencent cloud

Tencent Cloud Organization

  • Product Introduction
  • Purchase Guide
  • Operation Guide
    • Console Overview
    • Organization Settings
    • Department Management
    • Member Account Management
    • Member Finance Management
    • Member Access Management
    • Resource Management
    • Member Audit
    • Identity Management
  • API Documentation
    • History
    • Introduction
    • API Category
    • Making API Requests
    • Organization Settings APIs
    • Department and Member Management APIs
    • ListOrganizationIdentity
    • Unified Member Login APIs
    • Organization Service Management APIs
    • Organization Management Policy APIs
    • Resource Sharing APIs
    • Identity Center Management APIs
    • Identity Center User Management APIs
    • Identity Center User Group Management APIs
    • Identity Center Management SCIM Synchronization APIs
    • Identity Center Single Sign-On Management APIs
    • Identity Center Permission Configuration Management APIs
    • Identity Center Multi-Account Authorization Management APIs
    • Identity Center Sub-User Synchronization Management APIs
    • Data Types
    • Error Codes
    • TCO API 2018-12-25
  • Related Agreement
  • FAQs
  • Glossary

Overview of Multi-Account Authorization

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-07-17 14:50:59
Diterjemahkan oleh AI
On the Multi-account Authorization page, you can configure CAM user synchronization and CAM role synchronization based on the directory structure of the group account.

Difference explanation

Identity Management users can access the account's cloud resources through CAM roles or CAM users. The differences between the two methods are shown in the table below.
Access method
Note
Synchronization Method
Related Documents
Configuring CAM Role Synchronization
In Identity Management of a group account, an enterprise accesses Tencent Cloud users. Through permission configuration and CAM role synchronization, it enables users to log in to the CAM role within a member account via single sign-on and then access the cloud resources of that member account.
When configuring CAM role synchronization, the Identity Management will initiate tasks for each triplet (User-Account-Permission Configuration).
After synchronization, the access privileges in CAM are finalized and cannot be modified in CAM.
Configuring CAM User Synchronization
In Identity Management of a group account, an enterprise accesses Tencent Cloud users. By configuring CAM user synchronization, it enables users to log in to the CAM user within a member account and then access the cloud resources of that member account.
When configuring CAM user synchronization, the Identity Management will initiate tasks for each tuple (User-Account).
After synchronization, the access permissions in CAM are empty and need to be configured within CAM.

CAM Role Synchronization Explanation

If you want to grant multiple accounts, multiple identities, and multiple access configurations in a one-time batch authorization, you can go to TCO > Identity Management's multi-account permission management page, browse the account directory tree, and perform the following operations:
1. Select one or more accounts in the account tree as authorization targets.
2. Select one or more Identity Management identities.
3. Select one or more access configurations.
4. Click Configure CAM Role Synchronization, and the Identity Management service will complete the authorization for you in bulk.
In bulk authorization, if duplicate authorization is attempted for some existing batch authorizations, the operation will fail. However, newly added authorizations in the same batch will succeed.
Each time permissions are added, the Identity Management will initiate an asynchronous task for each triplet (Identity-Account-Permission Configuration).

CAM User Synchronization Explanation

If you want to grant multiple accounts and multiple identities in a one-time batch authorization, you can go to TCO > Identity Management's multi-account permission management page, browse the account directory tree, and perform the following operations:
1. Select one or more accounts in the account directory tree.
2. Select one or more Identity Management identities.
3. Click Configure CAM User Synchronization, and the Identity Management service will complete the synchronization for you in bulk.
In bulk synchronization, if a duplicate operation is attempted for some existing synchronizations, the operation will fail. However, newly added synchronizations in the same batch will succeed.
After successful configuration, a CAM user with the same name as the Identity Management user will be created in the target account.
Authorization: Access the target account to authorize the CAM user created by Back.
CAM users have no permissions by default. You need to grant them the appropriate permissions for the corresponding resources.
Identity Management users access the authorized resources in the target account through the CAM user identity.
For specific operations, please see Configuring CAM User Synchronization.



Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan