Questions and answers about Identity and Access Management
General questions
What do I need Yandex Identity and Access Management for?
The IAM service controls access to resources and lets you configure access rights. You determine who should have rights for a certain resource and what these rights are, while IAM grants access according to the assigned rights.
IAM enables you to:
- Manage access permissions for resources by assigning and revoking roles.
- Create service accounts. These are special accounts used for managing Yandex Cloud resources via the API.
- Get an IAM token for API authentication.
Other Yandex Cloud services use the IAM API to give you more options for managing access to their resources. For example, Yandex Compute Cloud additionally provides the compute.images.user role to manage access to disk images.
How do I get started with IAM?
To get started with IAM, you need to register with Yandex Cloud. Once registered, you will be able to use the IAM features.
How much does it cost to use IAM?
Using IAM is free of charge.
Can I get logs of my operations in Yandex Cloud?
Yes, you can request information about operations with your resources from Yandex Cloud logs. Do it by contacting support
Logging in and accessing resources
How do I log in to the management console?
Go to the management console page
If not logged in to your Yandex or Yandex 360 account yet, click Log in. If you do not have an account yet, click Register. For more information, see (https://yandex.com/support/passport/auth.html).
What do I do if I get the User has to accept the End User License Agreement error when trying to get an IAM token?
When getting an IAM token via the Yandex Cloud CLI, Terraform, or a direct request to the API, you may get one of these errors:
User has to accept the End User License Agreement to get an IAM tokenUser has to accept the End User License Agreement and Privacy Policy to get an IAM token
The error means that the user requesting the IAM token has not accepted the required agreements yet.
To solve the error, log in to the user’s account and accept the license agreement and privacy policy on the agreement acceptance page
If instead of the agreement acceptance page you see a folder in the management console, log out of the account and then log back in. You can also try opening the link in incognito mode or in another browser.
If the agreements are already accepted, make sure the token in the CLI profile, Terraform provider settings, or the API request belongs to the same user. For an OAuth token, you can figure out the owner by requesting user infologin field of the response will contain the Yandex account login.
To work in the CLI as a federated or local user, configure authentication appropriately:
- Authenticating with the Yandex Cloud CLI as a federated user
- Authenticating in the Yandex Cloud CLI as a local user
How are access permissions verified?
Before performing an operation with a resource, such as creating a VM, IAM checks whether the user has all the required permissions. If any of the required permissions are missing, the operation will fail and Yandex Cloud will report an error. For more information, see How access management works in Yandex Cloud.
What is a resource?
A resource is a Yandex Cloud entity you can manage through operations, such as creating, updating, viewing, or deleting. Here are some examples of resources: VMs, disks, service accounts, clouds, and folders. For more information, see Yandex Cloud resource hierarchy in the Resource Manager guides.