Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Platform overview
    • Platform architecture
    • Regions
    • Network overview
    • Public IP address ranges
    • User interaction with resources
    • Zones of control in MDB
    • Zones of control in Managed Service for Kubernetes
    • Zones of control in Yandex Data Processing
    • Deleting user data
    • Obtaining the information you need to request the Russian Ministry of Digital Development to whitelist a resource
    • Service list
    • Release stages
    • Observability tools for monitoring and logging
    • SLA
    • Quotas and limits
    • Release notes
    • Troubleshooting
    • Overview
    • Mobile app
    • API
    • Working with the Yandex Cloud CLI and API in Microsoft Windows
  • Tools for working with documentation

In this article:

  • Yandex Cloud resources
  • Users
  • Access management
  1. Yandex Cloud platform
  2. User interaction with resources

Interaction between users and Yandex Cloud resources

Written by
Yandex Cloud
Updated at July 13, 2026
View in Markdown
  • Yandex Cloud resources
  • Users
  • Access management

All Yandex Cloud services work based on the common resource and role model. Its underlying entity is organization that combines different types of resources and users in a single workspace. You add and manage users at the organization level; learn more here.

Users and resources hierarchy

Yandex Cloud resourcesYandex Cloud resources

When using Yandex Cloud services, you create resources: VMs, managed database and Kubernetes clusters, registries, secrets, and more. Most services store the resources they create in folders. Folders belong to clouds, and clouds belong to organizations.

In addition, organizations may have the following enabled: Yandex DataSphere, a Yandex DataLens instance, as well as Yandex Tracker, Yandex Wiki, Yandex Forms, and Yandex SpeechSense. All of them store their resources on their own, yet are able to exchange information with other services within the same organization. Organizations do not interact with each other.

In the Cloud Center interface, you can look up the clouds and services existing in your organization.

Learn more about the resource hierarchy in Yandex Cloud.

UsersUsers

Each Yandex Cloud user has an account of their own used for identification when performing operations with resources. This can be either a Yandex ID account, a federated account of an identity federation, or a local account from a user pool. In addition, there are service accounts: a special type of account your software can use to perform operations with Yandex Cloud resources. Learn more about accounts.

Each user belongs to at least one organization. When logging in to Yandex Cloud with your Yandex ID for the first time, you will be prompted to register your own organization. After creating an organization, you can enable and disable Yandex Cloud services, create clouds, folders, and other resources.

You can invite other members with Yandex accounts to your organization to grant them access to its services and resources. If your company already uses a different identity management system, e.g., Active Directory or Keycloak, you can set up an identity federation. This will allow company employees to use their corporate accounts to access Yandex Cloud services. In addition, you can create a user pool in your organization and, by adding a domain to it, create local user accounts in the organization.

For bulk access management, you can arrange users into groups.

For more information about managing users and user groups, see Yandex Identity Hub guides.

Access managementAccess management

Access to Yandex Cloud resources is managed through roles and access policies. For an account (subject) to be able to perform an action with a resource (object), the account or group this account belongs to must get relevant roles for that resource, and the action itself must not be prohibited by access policies. Basically, each role is a list of permitted object operations. Permissions to access Yandex Cloud resources are managed by Yandex Identity and Access Management.

To authenticate users, Yandex Cloud services request credentials. The type of data requested depends on the account type, the service, and request interface. When using the API, the folder ID is also required to uniquely identify the resource and verify the permissions. If actions are performed on behalf of a service account, the ID of its folder is used by default.

Was the article helpful?

Previous
Public IP address ranges
Next
Zones of control in MDB
© 2026 Direct Cursus Technology L.L.C.