Yandex Cloud
Search
Contact UsGet started
  • Blog
  • Pricing
  • Documentation
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • ML & AI
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Customer Stories
    • Gateway to Russia
    • Cloud for Startups
    • Education and Science
  • Blog
  • Pricing
  • Documentation
Yandex project
© 2025 Yandex.Cloud LLC
Yandex Identity and Access Management
    • Overview
    • How to manage access to resources
    • How to work with service accounts
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • Getting started
  • Add a user with a Yandex account to your organization
  • Assign roles to the user
  • Revoke assigned roles
  • What's next
  1. Getting started
  2. How to manage access to resources

Getting started with IAM

Written by
Yandex Cloud
Updated at April 9, 2025
  • Getting started
  • Add a user with a Yandex account to your organization
  • Assign roles to the user
  • Revoke assigned roles
  • What's next

To get started with IAM, add a user to your organization and grant them access to a resource in one of your clouds. Learn more about organizations, resources, and users.

Getting started

  1. Log in to the management console. If not signed up yet, navigate to the management console and follow the on-screen instructions.

  2. Make sure that you have the required roles:

    1. In the management console, select the appropriate cloud from the list on the left. Example:

      image

    2. Navigate to the Access bindings tab.

    3. Specify your account in the search bar.

    4. Check that your account has the following roles:

      • Organization owner (organization-manager.organizations.owner) or administrator (organization-manager.admin)
      • Cloud owner (resource-manager.clouds.owner) or administrator (admin)
  3. On the Yandex Cloud Billing page, make sure you have a linked billing account and its status is ACTIVE or TRIAL_ACTIVE. If you do not have a billing account yet, create one.

  4. If you do not have any users to add to the cloud, you can create a new Yandex account and grant this account access to the cloud.

Add a user with a Yandex account to your organization

Management console
  1. Log in to the cloud administrator account.

  2. Log in to the management console.

  3. Select the appropriate cloud from the list on the left.

  4. Navigate to the Access bindings tab.

  5. In the top-right corner, click and select Invite users.

  6. Enter the email addresses of the users you want to invite to the organization (e.g., login@yandex.com).

    You can send invitations to any email address. Invited users will be able to select the appropriate Yandex account once they accept the invitation.

  7. Click Send invitation.

The user will be able to log in to the organization upon accepting the invitation via the emailed link and selecting an account for log-in. To access the services enabled for the organization, the users you invited simply need to log in to their Yandex account.

Assign roles to the user

To specify which operations the user can perform, assign relevant roles to the user. For example, allow the user to view cloud resources and manage a folder:

Management console
  1. Assign the user a role in the cloud:

    1. In the management console, on the left, select a cloud.
    2. Go to the Access bindings tab.
    3. Click Configure access.
    4. In the window that opens, select User accounts.
    5. Select a user from the list or search by user.
    6. Click Add role.
    7. Select the resource-manager.viewer role. This role enables you to read cloud information, including the access rights list.
    8. Click Save.
  2. Assign the user a role in the folder:

    1. In the management console, select the appropriate folder.
    2. Go to the Access bindings tab.
    3. Click Configure access.
    4. In the window that opens, select User accounts.
    5. Select a user from the list or search by user.
    6. Click Add role.
    7. Select the resource-manager.editor role. This role enables you to read folder information, including the access rights list, as well as edit and delete the folder.
    8. Click Save.

Revoke assigned roles

If the assigned roles are no longer needed, revoke them:

Management console
  • To revoke a role only in the folder:

    1. On the start page of the management console, select the folder.
    2. Go to the Access bindings tab.
    3. Select a user from the list and click next to the username.
    4. Click Edit roles.
    5. Click next to the role you wish to revoke.
    6. Click Save.
  • To revoke a role in the cloud:

    1. On the start page of the management console, select the cloud.
    2. Go to the Access bindings tab.
    3. Select a user from the list and click next to the username.
    4. Click Edit roles.
    5. Click next to the role you wish to revoke.
    6. Click Save.

What's next

  • The step-by-step guides will help you perform specific tasks in Identity and Access Management.
  • Learn about access management in Yandex Cloud.
  • See the best practices for using Yandex Cloud securely.
  • Learn how to get started with Cloud Organization.
  • Learn about authentication in Yandex Cloud.
  • Learn how to work with service accounts.
  • See answers to frequently asked questions.

Was the article helpful?

Previous
Overview
Next
How to work with service accounts
Yandex project
© 2025 Yandex.Cloud LLC