Product functions
Centralized authorization and decentralized access control
IAM provides centralized management of all resource permissions on Baidu AI Cloud, guiding users to assign specific resource permissions within the cloud account to enterprise or team members according to their roles, achieving efficient resource sharing and decentralized control.
Fine-grained permission management
IAM includes predefined system policies and customizable policies. System policies regulate permissions at the product level, covering all resource instances within a product. For products that support custom policies, permissions can be assigned at a granular level, such as granting one user read-only access to a specific BCC server while allowing another user full administrative privileges for a particular BOS bucket.
Cross-account resource access
In certain service scenarios, such as outsourced operations, you need cross-account access to resources of other cloud accounts is required. IAM provides [role management](IAM/Operation guide/Role Management/Managing Roles.md) function, which enables users to temporarily obtain access to other cloud accounts upon receiving explicit authorization, thereby facilitating resource access operations across accounts.
Multi Factor Authentication
Multi-Factor Authentication (MFA) ensures secure access to cloud accounts. IAM supports both SMS-based and virtual MFA App-based secondary authentication methods, safeguarding critical operations within cloud accounts and enhancing security.
Federated identity
Medium-to-large enterprise customers typically have internal IT identity management systems integrated with other corporate services. When using Baidu AI Cloud, they expect to treat it as one of their Service Providers (SP) for federated identity certification, with the enterprise itself acting as the Identity Provider (IdP). IAM provides federated identity management supporting the SAML 2.0 standard protocol. Through simple configuration, users can integrate own internal identity management system with Baidu AI Cloud's account system. For details, refer to [External Account Access](IAM/Operation guide/Enterprise Account Integration/Federated Login Overview.md).
Audit support
Key IAM user operations have been included into Baidu Cloud Trail (BCT) of Baidu AI Cloud, enabling 90-day operation record queries and trace creation for long-term audit record storage.
