Group Management
Overview
A group represents a collection of users, typically individuals with similar responsibilities (e.g., R&D or O&M teams), categorized to enhance user management efficiency by enabling permission segregation.
Common scenarios
- If an IAM user within a group undergoes role changes, there is no need to adjust the permissions for that specific user. Simply remove the user from the group.
- When the responsibilities of the team associated with a group change, there's no need to modify permissions for each IAM user individually. Instead, you can adjust the permission policy for the group.
Prerequisites
Before using group functions, you must be the root account of Baidu AI Cloud, an IAM user with system administrator permissions, or an IAM user granted the IAMFullControlAccessPolicy permission.
Group creation and authorization
- Sign in to the Baidu AI Cloud Management Console, select Identity and Access Management - Group Management, and click Create New Group.

- Enter the essential details of the new group, such as the group name (letters, numbers, and special characters ".-\@_" are allowed). Additional notes can also be included.

- In policy management, assign permission policies to newly created groups to define the access restrictions for the group.

- In group management, add users to the newly created groups; users inherit group permissions while retaining their own individual permissions. IAM users and message contacts can also be added.

- Click OK to complete user creation.
Modify policies for a group
Modify policies for existing groups. Click Edit in policy management to modify strategies for group members.

Modify members for a group
Modify members for existing groups. Click Edit to add or remove group members in member management.
View group information
Click the corresponding group name to enter the created group, where users can view group details such as group policies and group members.
Delete group
Click Delete and the OK to remove the created group.
Note: Deleted groups cannot be restored. Any IAM users previously authorized under the group will lose access rights, potentially disrupting online services. Therefore, ensure the group's policies are no longer needed before deletion.

