Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity and Access Management
    • Overview
      • Overview
      • Service accounts
    • Service access to user resources
    • Identity federations
    • Workload identity federations
    • Quotas and limits
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • Yandex account
  • Use cases
  • Federated account
  • Use cases
  • Local user
  • Service account
  • Use cases
  1. Concepts
  2. Accounts in Yandex Cloud
  3. Overview

Accounts in Yandex Cloud

Written by
Yandex Cloud
Updated at July 23, 2026
View in Markdown
  • Yandex account
    • Use cases
  • Federated account
    • Use cases
  • Local user
  • Service account
    • Use cases

Yandex Cloud uses Yandex accounts, service accounts, federated accounts, and local accounts.

Note

Billing accounts are not used for managing resources in Yandex Cloud and are not part of IAM. For more information, see Billing accounts in the Yandex Cloud Billing documentation.

Yandex accountYandex account

Yandex account: Your Yandex or Yandex 360 account. Use this account type in the following cases:

  • If you do not need to set up access permissions for your applications. Otherwise, use a service account.
  • For smaller teams if you did not set up an identity federation in your organization (e.g., with Active Directory or Google Workspace). Otherwise, use federated accounts.

To better safeguard your resources from unauthorized access:

  1. Enable two-factor authentication for your Yandex account.
  2. Request users you add to your organization to enable two-factor authentication as well.
  3. In the organization security settings, enable the two-factor authentication requirement. This way, only users with two-factor authentication enabled will be able to access resources.

Use casesUse cases

  • Creating an interactive serverless application using WebSocket

Federated accountFederated account

A federated account is a user account from an identity federation, e.g., Active Directory.

With identity federations, a business can enable single sign-on to Yandex Cloud via their server. This allows the company employees use their corporate accounts to access Yandex Cloud.

Use federated accounts if you need to grant Yandex Cloud access to a large number of employees.

For more information, see SAML-compatible identity federations.

Note

The federated user's attributes are loaded into their profile in the Yandex Identity Hub organization after the user's first authentication to Yandex Cloud.

Use casesUse cases

  • Auto Unseal in Hashicorp Vault

Local userLocal user

Local users are linked only to the domain, their credentials are stored only in Yandex Cloud as part of a user pool. Local users are created in a user pool, exist within a single organization, and cannot create a new one. The pool administrator can flexibly configure authentication, including by setting a password policy, and set the expiration date for local user accounts.

Use local users if you need to manage employee accounts centrally directly in Yandex Cloud.

Local users get authenticated in Yandex Cloud with the help of Login Discovery without using any external authentication providers.

Service accountService account

A service account is an account that can be used by a program to manage resources in Yandex Cloud.

Service accounts allow you to set up flexible access to your resources and minimize risks associated with excessive permissions. Use this account type for your applications, CLI, Terraform, and Yandex Cloud API. For more information, see Service accounts.

Use casesUse cases

  • Getting started with Terraform

Was the article helpful?

Previous
Overview
Next
Service accounts
© 2026 Direct Cursus Technology L.L.C.