Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity and Access Management
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes
    • General questions
    • Logging in and accessing resources
    • All questions on one page

In this article:

  • General questions
  • Logging in and accessing resources
  1. FAQ
  2. All questions on one page

Questions and answers about Identity and Access Management

Written by
Yandex Cloud
Updated at October 9, 2026
View in Markdown
  • General questions
  • Logging in and accessing resources

General questionsGeneral questions

What do I need Yandex Identity and Access Management for?What do I need Yandex Identity and Access Management for?

The IAM service controls access to resources and lets you configure access rights. You determine who should have rights for a certain resource and what these rights are, while IAM grants access according to the assigned rights.

IAM enables you to:

  • Manage access permissions for resources by assigning and revoking roles.
  • Create service accounts. These are special accounts used for managing Yandex Cloud resources via the API.
  • Get an IAM token for API authentication.

Other Yandex Cloud services use the IAM API to give you more options for managing access to their resources. For example, Yandex Compute Cloud additionally provides the compute.images.user role to manage access to disk images.

How do I get started with IAM?How do I get started with IAM?

To get started with IAM, you need to register with Yandex Cloud. Once registered, you will be able to use the IAM features.

How much does it cost to use IAM?How much does it cost to use IAM?

Using IAM is free of charge.

Can I get logs of my operations in Yandex Cloud?Can I get logs of my operations in Yandex Cloud?

Yes, you can request information about operations with your resources from Yandex Cloud logs. Do it by contacting support.

Logging in and accessing resourcesLogging in and accessing resources

How do I log in to the management console?How do I log in to the management console?

Go to the management console page.

If not logged in to your Yandex or Yandex 360 account yet, click Log in. If you do not have an account yet, click Register. For more information, see (https://yandex.com/support/passport/auth.html).

What do I do if I get the error when trying to get an IAM token?What do I do if I get the User has to accept the End User License Agreement error when trying to get an IAM token?

When getting an IAM token via the Yandex Cloud CLI, Terraform, or a direct request to the API, you may get one of these errors:

  • User has to accept the End User License Agreement to get an IAM token
  • User has to accept the End User License Agreement and Privacy Policy to get an IAM token

The error means that the user requesting the IAM token has not accepted the required agreements yet.

To solve the error, log in to the user’s account and accept the license agreement and privacy policy on the agreement acceptance page. Then try to get the IAM token again.

If instead of the agreement acceptance page you see a folder in the management console, log out of the account and then log back in. You can also try opening the link in incognito mode or in another browser.

If the agreements are already accepted, make sure the token in the CLI profile, Terraform provider settings, or the API request belongs to the same user. For an OAuth token, you can figure out the owner by requesting user info: the login field of the response will contain the Yandex account login.

To work in the CLI as a federated or local user, configure authentication appropriately:

  • Authenticating with the Yandex Cloud CLI as a federated user
  • Authenticating in the Yandex Cloud CLI as a local user

How are access permissions verified?How are access permissions verified?

Before performing an operation with a resource, such as creating a VM, IAM checks whether the user has all the required permissions. If any of the required permissions are missing, the operation will fail and Yandex Cloud will report an error. For more information, see How access management works in Yandex Cloud.

What is a resource?What is a resource?

A resource is a Yandex Cloud entity you can manage through operations, such as creating, updating, viewing, or deleting. Here are some examples of resources: VMs, disks, service accounts, clouds, and folders. For more information, see Yandex Cloud resource hierarchy in the Resource Manager guides.

Was the article helpful?

Previous
Logging in and accessing resources
© 2026 Direct Cursus Technology L.L.C.