Getting started with Cloud Organization
To get started, create an organization and add users to it.
Organization is a workspace that combines different types of Yandex Cloud resources and users. Learn more about organizations, resources, and users.
Create an organization
-
Log in
to your Yandex account. If you do not have an account, create one. -
Go to Yandex Cloud Organization
. -
Read the Yandex Cloud terms of use and click Log in.
-
Enter your company name and description.
-
Click Create organization.
After registering, you become the organization owner. You will be able to manage employee accounts, as well as connect and disable services.
Add employees
To provide your employees with access to the organization's services, connect them using their Yandex accounts. If your company already uses a different account management system (such as Active Directory or Google Workspace), configure an identity federation so that your employees can use their work accounts to access Yandex Cloud services.
Connect employees with Yandex accounts
If your employees have Yandex accounts (for example, login@yandex.com
), they can use them to access the Yandex Cloud services enabled in your organization.
To connect employees with Yandex accounts:
-
In the left-hand panel, select Users
. -
In the top-right corner, click Invite users.
-
Enter the email addresses of the users you want to invite to the organization (e.g.,
login@yandex.com
).You can send invitations to any email address. Invited users will be able to select the appropriate Yandex account once they accept the invitation.
-
Click Send invitation.
The users will be connected to the organization upon accepting the invitation via the emailed link and selecting an account for log-in.
Configure an identity federation
An identity federation is a technology that allows you to implement a Single Sign-On (SSO) authentication scheme and use corporate accounts to log in to Yandex Cloud Organization. In this case, your corporate account management system acts as an identity provider (IdP).
To configure your identity federation, follow these steps:
-
In the left-hand panel, select Federations
. -
Click Create federation.
-
Enter the federation name and description.
-
In the Cookie lifetime field, specify the time before the browser asks the user to re-authenticate.
-
In the IdP Issuer field, specify the IdP server ID to be used for authentication. The IdP server must send the same ID in its response to Cloud Organization during user authentication.
Note
ID format depends on the type of IdP server you use (for example, Active Directory or Google Workspace).
-
In the Single Sign-On method field, choose POST.
-
In the Link to the IdP login page field, specify the address of the page that the browser redirects the user to for authentication.
-
Add an identity provider certificate to the created federation.
-
Enable Automatically create users to add authenticated users to your organization automatically.
If you do not enable this option, you will need to manually add your federated users.
-
Configure the identity provider's server to transmit successful authentication information and user attributes to Yandex Cloud.
User attributes supported by Yandex Cloud Organization services are listed in identity federation setup guides for different identity providers: