Currently Supported Product Lines

IAM IAM

  • API Reference
    • Common request header and common response header
    • Data type
    • Error code
    • Feature Update Records
    • General Description
    • Introduction
    • Service domain
    • STS-Related Interfaces
  • API Reference_IAM
    • Common request header and common response header
    • Data type
    • Error code
    • General Description
    • Group management API
    • Introduction
    • Policy management API
    • Role Management Interfaces
    • Service domain
    • User management API
  • FAQs
    • Common Questions Overview
    • FAQs related to IAM users
    • FAQs related to product permissions
  • Function Release Records
  • Operation guide
    • Account Security Audit
    • Enterprise Account Integration
      • Federated Login Overview
      • IAM Role-based SSO
      • IAM User-based SSO
    • Group Management
    • Message Center
    • Permission Policies
      • ACL
      • Authorization
      • Managing IAM Policies
      • Permission Policy Overview
      • Policy Authentication Evaluation Logic
      • Strategy type
      • Tag-Based Authorization and Authentication
    • Role Management
      • Common scenarios
      • Create role
      • FAQs
      • Managing Roles
      • Overview
      • Related concepts
      • Using Roles
    • Settings
    • User
      • IAM User Operations
      • Two-Factor Authentication
      • User management
    • User Anomaly Behavior Analysis (Public Beta)
      • Risk Behavior Management
  • Operation records
    • Cloud Trail (Public Beta)
  • Product Announcement
    • Baidu Intelligent Cloud Enables Login Protection MFA Multi-Factor Authentication Notification for All Users
  • Product Description
    • Application scenarios
    • Concepts
    • Currently Supported Product Lines
    • Product functions
    • Product overview
    • System Restrictions
    • Enterprise Organization vs Identity and Access Management
  • Product pricing
    • Product pricing
  • Quick Start
    • Create groups and grant permissions
    • Creating IAM User Administrators
  • SDK
    • Go-SDK
      • Error handling
      • Group management API
      • Initialize SDK
      • Install the SDK Package
      • Overview
      • Policy management API
      • Role Management Interfaces
      • User management API
      • Version Change Records
    • Java-SDK
      • Error code
      • Group management API
      • Initialization
      • Install the SDK Package
      • Overview
      • Policy management API
      • Role Management Interfaces
      • User management API
      • Version Change Records
    • Python-SDK
      • Error code
      • Group management API
      • Initialization
      • Install the SDK Package
      • Overview
      • Policy management API
      • Role Management Interfaces
      • User management API
      • Version Change Records
  • Testing Knowledge Base SDK
  • Typical Practices
    • Baidu Intelligent Cloud Partner Guide to Creating IAM Users
    • User Management and Permission Assignment
All documents
menu
No results found, please re-enter

IAM IAM

  • API Reference
    • Common request header and common response header
    • Data type
    • Error code
    • Feature Update Records
    • General Description
    • Introduction
    • Service domain
    • STS-Related Interfaces
  • API Reference_IAM
    • Common request header and common response header
    • Data type
    • Error code
    • General Description
    • Group management API
    • Introduction
    • Policy management API
    • Role Management Interfaces
    • Service domain
    • User management API
  • FAQs
    • Common Questions Overview
    • FAQs related to IAM users
    • FAQs related to product permissions
  • Function Release Records
  • Operation guide
    • Account Security Audit
    • Enterprise Account Integration
      • Federated Login Overview
      • IAM Role-based SSO
      • IAM User-based SSO
    • Group Management
    • Message Center
    • Permission Policies
      • ACL
      • Authorization
      • Managing IAM Policies
      • Permission Policy Overview
      • Policy Authentication Evaluation Logic
      • Strategy type
      • Tag-Based Authorization and Authentication
    • Role Management
      • Common scenarios
      • Create role
      • FAQs
      • Managing Roles
      • Overview
      • Related concepts
      • Using Roles
    • Settings
    • User
      • IAM User Operations
      • Two-Factor Authentication
      • User management
    • User Anomaly Behavior Analysis (Public Beta)
      • Risk Behavior Management
  • Operation records
    • Cloud Trail (Public Beta)
  • Product Announcement
    • Baidu Intelligent Cloud Enables Login Protection MFA Multi-Factor Authentication Notification for All Users
  • Product Description
    • Application scenarios
    • Concepts
    • Currently Supported Product Lines
    • Product functions
    • Product overview
    • System Restrictions
    • Enterprise Organization vs Identity and Access Management
  • Product pricing
    • Product pricing
  • Quick Start
    • Create groups and grant permissions
    • Creating IAM User Administrators
  • SDK
    • Go-SDK
      • Error handling
      • Group management API
      • Initialize SDK
      • Install the SDK Package
      • Overview
      • Policy management API
      • Role Management Interfaces
      • User management API
      • Version Change Records
    • Java-SDK
      • Error code
      • Group management API
      • Initialization
      • Install the SDK Package
      • Overview
      • Policy management API
      • Role Management Interfaces
      • User management API
      • Version Change Records
    • Python-SDK
      • Error code
      • Group management API
      • Initialization
      • Install the SDK Package
      • Overview
      • Policy management API
      • Role Management Interfaces
      • User management API
      • Version Change Records
  • Testing Knowledge Base SDK
  • Typical Practices
    • Baidu Intelligent Cloud Partner Guide to Creating IAM Users
    • User Management and Permission Assignment
  • Document center
  • arrow
  • IAMIAM
  • arrow
  • Product Description
  • arrow
  • Currently Supported Product Lines
Table of contents on this page
  • Platform module permissions
  • Description of IAM-integrated product services
  • Computing
  • Network
  • Security and management
  • Storage and CDN
  • Data analysis
  • Database
  • Intelligent multimedia service
  • IoT service
  • Website service
  • Application service

Currently Supported Product Lines

Updated at:2025-10-27

IAM, Baidu AI Cloud's identity and access management service, offers centralized permission management for cloud platform products. Relevant cloud services must integrate with IAM for in-product permission control. This document provides detailed information about cloud products integrated with IAM, including supported permission granularity and relevant documentation. Currently, IAM provides two main service types for cloud products:

  • Identity and Access Management (IAM) primarily addresses identity, authorization, and certification between primary and IAM users
  • Security Token Service (STS), a temporary identity management service provided by IAM for products and services.

Platform module permissions

Platform policies detail the general service module policies of Baidu AI Cloud, covering system-level administration, operations, read-only access, finance, ticket, and certificate management, among others. Platform policies are part of IAM's system policies.

Permission name Policy description Related documents
System administrator permissions Possess permissions to manage all Baidu AI Cloud resources -
System operation and maintenance permission Include all O&M product lines for access authentication -
System read-only permission Include all read-only product lines for access authentication -
Financial permissions Possess permissions to view, pay, and cancel orders -
Certificate management Support certificate read-only and O&M permissions [Certificate management](Reference/Certificate management/Identity and access management.md)
Ticket system administrator (TicketFullControlPolicy) Grants permission to manage global tickets, including creating, viewing, replying to, and deleting all account-level tickets. -
Basic ticket management permission (TicketUserControlPolicy) Permission to manage their own tickets as an IAM user, including creating tickets, as well as viewing, replying to, and deleting tickets for the currently signed-in IAM user. -
IAM system administrator (IAMFullControlAccessPolicy) Possess permissions to manage multi-user access control -
IAM read-only permission (IAMReadAccessPolicy) Possess read-only multi-user access control permissions, including the authority to download access reports -
AK management permission (IAMManageAccessKeyPolicy) Add, delete or manage IAM user's AccessKey permissions. If Programmatic Access is checked during creation, this permission is granted by default -
BCT management permission Possess all permissions for managing BCT records, downloading BCT logs, managing traces, etc. -
BCT read-only permission Possess read-only permission for managing BCT records, downloading BCT logs, viewing traces, etc. -

Description of IAM-integrated product services

This section describes product services integrated with IAM and STS. The meanings of fields in the following table are explained as follows:

  • Product name: Chinese + English abbreviations of Baidu AI Cloud products and services;
  • Permission granularity: Including service-level and resource-level. The service-level authorizes entire cloud products, while the resource-level enables precise authorization to instances (e.g., a specific BCC server)
  • System-supported operational permissions: System policies supported by cloud products at the service-level permission granularity
  • Security Token Service (STS): ✅ denotes supporting while - denotes not supporting;
  • Tag authorization: Filter permissions and resources for authorization based on selected tags. ✅ indicates supporting while - indicates not supporting;
  • Related documentation: A hyperlink indicates that the product has associated permission documentation, whereas a "-" signifies that no documentation is currently available.

Computing

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag authorization Related documents
Baidu Cloud Compute (BCC) Resource-level Read-only, O&M, and management permissions ✅ ✅ BCC
Dedicated Cloud Compute (DCC) Resource-level Read-only, O&M, and management permissions ✅ ✅ -
Baidu Baremetal Compute (BBC) Resource-level Support read-only and O&M permissions ✅ - -
Cloud container engine (CCE) Resource-level Development, O&M, and management permissions ✅ - [CCE](CCE/Operation guide/Identity and access management.md)
Application engine professional BAEPRO Resource-level - ✅ - [BAEPRO](BAE-Pro/Operation guide/Multi-user Collaboration.md)
Cloud Function Computing Service-level Read-only and management permissions - - -
Lightweight application server LS Resource-level Read-only, O&M, and management permissions - - LS

Network

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
EIP Resource-level Read-only, O&M, and management permissions ✅ ✅ [EIP](EIP/Operation guide/Identity and access management.md)
EIPGROUP Resource-level Read-only, O&M, and management permissions ✅ - [EIPGROUP](EIP/Operation guide/Identity and access management.md)
EIP_BP Service-level Read-only, O&M, and management permissions - - [EIP_BP](EIP/Operation guide/Identity and access management.md)
Baidu Load Balance (BLB) Resource-level Read-only, O&M, and management permissions ✅ ✅ [BLB](BLB/Operation guide/Identity and access management.md)
Virtual Private Cloud (VPC) Resource-level Read-only, O&M, and management permissions ✅ ✅ [NETWORK](VPC/Operation guide/Identity and access management.md)
Subnet Resource-level Read-only, O&M, and management permissions ✅ - [subnet](VPC/Operation guide/Identity and access management.md)
securityGroup Resource-level Read-only, O&M, and management permissions ✅ ✅ [Security group](VPC/Operation guide/Identity and access management.md)
Access Control List (ACL) Resource-level Read-only and O&M permissions ✅ - [ACL](VPC/Operation guide/Identity and access management.md)
Route Table (Route) Resource-level Read-only and O&M permissions ✅ - [Route table](VPC/Operation guide/Identity and access management.md)
Dedicated gateway Resource-level Read-only, O&M, and management permissions ✅ - [Dedicated gateway](VPC/Operation guide/Identity and access management.md)
VPN gateway Resource-level Read-only, O&M, and management permissions ✅ - [VPN gateway](VPC/Operation guide/Identity and access management.md)
NAT gateway Resource-level Read-only, O&M, and management permissions ✅ - [NAT gateway](VPC/Operation guide/Identity and access management.md)
IPv6 public gateway Resource-level Read-only, O&M, and management permissions - - [IPv6](VPC/Operation guide/Identity and access management.md)
Peering connections (PEERCONN) Resource-level Read-only, O&M, and management permissions ✅ - [Peering connections](VPC/Operation guide/Identity and access management.md)
Express tunnel (ET) Service-level Read-only, O&M, and management permissions - - [Express tunnel (ET)](VPC/Operation guide/Identity and access management.md)
Smart network access service (SMART_WAN) Service-level O&M and management permissions - - -
Cloud Smart Network (CSN) Service-level Management permission - - -
RESOLVER Service-level Read-only, O&M, and management permissions - - DNS

Security and management

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Intrusion Detection System (IDS) Resource-level Read-only and O&M permissions - - -
Web Application Firewall (WAF) Resource-level Read-only and O&M permissions ✅ - -
Host security client (HOSTEYE) Resource-level Read-only, O&M, and management permissions - - -
Anti-DDoS Attack Service (ADAS) Service-level Read-only, O&M, and management permissions ✅ - -
Anti-Fraud Detection (AFD) Resource-level Management permission - - AFD
Security Risk Detection (SRD) Resource-level Read-only, O&M, and management permissions ✅ - SRD
Baidu Cloud Trail (BCT) Service-level Read-only and management permissions - - -
SPRINGER Security and Privacy Compliance Platform (SPRINGER) Service-level Management permission - - SPRINGER
Cloud Firewall (CFW) Service-level Read-only and management permissions - - -

Storage and CDN

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Baidu object storage (BOS) Resource-level Read-only and management permissions ✅ ✅ [BOS](BOS/Console Operation Guide/Configuring BOS Multi-User Access Control.md)
Cloud Disk Server (CDS) Resource-level Read-only, O&M, and management permissions ✅ ✅ -
Content delivery network (CDN) Resource-level Read-only, O&M, and management permissions ✅ ✅ CDN
Cloud File System (CFS) Resource-level Read-only, O&M, and management permissions - - [CFS](CFS/Operation guide/Identity and access management.md)
Baidu Table Service (BTS) Resource-level Read-only and O&M permissions - - [BTS](BTS/Operation guide/Identity and access management.md)
Baidu edge computing (BEC) Service-level Read-only, O&M, and management permissions - - -

Data analysis

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Baidu MapReduce (BMR) Resource-level - ✅ - [BMR](BMR/Operation guide/Identity and access management.md)
Baidu Elasticsearch (BES) Resource-level Read-only, O&M, and management permissions ✅ - BES
Baidu Message Service (BMS) Resource-level Read-only, O&M, and management permissions - - [BMS](Kafka/Shared Edition/Quick Start/Identity and access management.md)
Baidu Log Service (BLS) Resource-level Read-only, O&M, and management permissions - - BLS

Database

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Relational Database Service (RDS) Resource-level Read-only, O&M, and management permissions ✅ ✅ [RDS](RDS/Operation guide/RDS for MySQL Operation Guide/Identity and access management.md)
Simple Cache Service (SCS) Resource-level Read-only, O&M, and management permissions ✅ ✅ [SCS](SCS/Operation guide/Redis Operation Guide/Identity and access management.md)
Document Database (MongoDB) Resource-level Read-only, O&M, and management permissions - - MongoDB
Database Audit (DBAudit) Service-level Read-only, O&M, and management permissions - - DBAudit
Gaia Database (GaiaDB) Resource-level Read-only, O&M, and management permissions - - GaiaDB-S
Data transmission service (DTS) Service-level Support read-only, O&M and management permissions - - DTS

Intelligent multimedia service

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Live Streaming Service (LSS) Service-level Read-only and management permissions ✅ - -
Video On Demand (VOD) Service-level Management permission ✅ - -
Multimedia Cloud Transcoding (MCT) Service-level Management and read-only permission ✅ - -
Video Content Review (VCR) Service-level Read-only and management permissions ✅ - -

IoT service

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Cloud Virtual Customer Assistant (CVCA) Resource-level - - - -
Time Series Database (TSDB) Resource-level - ✅ - [TSDB](TSDB/Operation guide/Identity and access management.md)
Baidu Intelligent Edge (BIE) Resource-level Read-only and management permissions - - BIE

Website service

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Hosting Management Expert (HME) Service-level Support read-only and management permissions - - -
Intelligent Traffic Manager (ITM) Service-level Support read-only and management permissions - - [ITM](ITM/Operation guide/Identity and access management.md)
Baidu Cloud Domain (BCD) Service-level Support read-only, O&M and management permissions ✅ - -

Application service

Product Name Permission granularity System-supported operation permissions Security Token Service (STS) Tag-based authorization Related documents
Short Messaging Service (SMS) Service-level Support read-only and management permissions ✅ - -

Previous
Concepts
Next
Product functions