Yandex Cloud
Search
Contact UsGet started
  • Blog
  • Pricing
  • Documentation
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • ML & AI
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Customer Stories
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Education and Science
    • Yandex Cloud Partner program
  • Blog
  • Pricing
  • Documentation
© 2025 Direct Cursus Technology L.L.C.
Yandex Cloud Desktop
  • Getting started
    • Desktops and their groups
    • Access control list (ACL)
    • Disks
    • Images
    • User desktop showcase
    • Quotas and limits
  • Access management
  • Pricing policy
  • Cloud Desktop events

In this article:

  • Example of access control in Cloud Desktop
  • See also
  1. Concepts
  2. Access control list (ACL)

Access control list (ACL)

Written by
Yandex Cloud
Updated at October 28, 2024
  • Example of access control in Cloud Desktop
  • See also

Yandex Cloud Desktop leverages Yandex Identity and Access Management roles for access control.

Cloud Desktop ACL is a list of permissions for a given desktop group.

By default, an empty ACL is created for each new desktop group. A user with the vdi.admin role can edit an ACL.

Using an ACL, you can grant desktop group access to:

  • Yandex Cloud user
  • Service account
  • Yandex Cloud Organization user group
  • Public group
  • System group

Each desktop is assigned to a specific Yandex Cloud user.

To connect to a desktop, the user gets a unique RDP file with a built-in IAM token. This means only a certain user can access the desktop.

The IAM token lifetime is 12 hours. Once it expires, the RDP file is no longer valid. To connect to the desktop, the user needs to request a new RDP file.

If a user is removed from the list of Yandex Cloud users for any reason, e.g., if they were transferred to a different department or suspected of unauthorized activity, their RDP file becomes invalid regardless of when it was issued.

Example of access control in Cloud DesktopExample of access control in Cloud Desktop

  1. The organization administrator (user with the organization-manager.admin role for the cloud) creates a Yandex Cloud Organization user group for which a desktop group will be deployed.

  2. The Cloud Desktop administrator (user with the vdi.admin role for the folder) creates a desktop group and grants permissions for it to a user group.

    The administrator can also create a custom image for the desktop group.

  3. The Cloud Desktop administrator creates a personal desktop for each memeber in the user group.

  4. A user group member gets authenticated using Yandex ID or Single Sign-On (SSO) on the User desktop showcase page. The showcase displays the desktops available to a given user.

  5. From the showcase, the user group member downloads the RDP file for the appropriate desktop and connects to it.

See alsoSee also

  • Getting started with Cloud Desktop
  • Access management
  • Changing desktop group access permissions

Was the article helpful?

Previous
Desktops and their groups
Next
Disks
© 2025 Direct Cursus Technology L.L.C.