S1104309GC10 AA Lab02iam
S1104309GC10 AA Lab02iam
S1104309GC10 AA Lab02iam
Overview
Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) lets you control who
has access to your cloud resources.
In this lab, we will help you create a compartment, group, user, and policy. We will also provide
the steps to create a dynamic group.
Note: We have instructions for accounts with and without Identity Domains enabled.
a. Create a compartment
b. Create a user
d. Create a policy
Tasks
2. Open the Main Menu and select Identity & Security. Under Identity,
click Compartments. A list of the compartments to which you have access appears.
a. Name: Enter a unique name for the compartment. The name must be unique across
all the compartments in your tenancy.
5. Click Create Compartment. The Child Compartment now appears in the list of
compartments.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Domains. A
list of domains in your tenancy appears.
2. Select the Domain that is allotted to you. Otherwise, you can click on the Default domain.
3. Under Identity domain, click Users. A list of the users in your domain appears.
d. Check the Use the same email address as the username. Do not select the
Assign cloud account administrator role check box.
In this practice, you’ll learn how to create a group, and add a user to a group.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Domains. A
list of domains in your tenancy appears.
3. Under Identity domain, click Groups. A list of the groups in your domain appears.
6. Select the user created earlier from the Users drop-down list, and then click Add. The user
now appears in the group.
7. Use the breadcrumb trail to go back to the Groups page and click Create Group.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Policies.
c. Compartment: If you want to attach the policy to a compartment other than the one
you’re viewing, select it from the drop-down list. Remember, where the policy is
attached controls who can later modify or delete it.
4. In the Policy Builder section, click Show manual editor and enter the policy statement.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Domains. A
list of domains in your tenancy appears.
a. Name: Enter a unique name for the group. The name must be unique across all groups
in your tenancy, including dynamic groups and user groups.
b. Description: Enter a friendly description.
6. Enter the Matching Rules. Resources that meet the rule criteria are members of the
dynamic group.
− For example, to include all instances that are in a specific compartment, add a rule
with the following syntax:
instance.compartment.id = '<compartment_ocid>'
7. Click Create. The dynamic group now appears in the list of dynamic groups.
Tasks
2. Open the Main Menu and select Identity & Security. Under Identity,
click Compartments. A list of the compartments to which you have access appears.
a. Name: Enter a unique name for the compartment. The name must be unique across
all the compartments in your tenancy.
5. Click Create Compartment. The Child Compartment now appears in the list of
compartments.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Users. A list of
users in your tenancy appears.
f. Description: This value could be the user’s full name, a nickname, or any other
descriptive information.
g. Email: Enter an email address for the user. This email address is used for
password recovery.
In this practice, you’ll learn how to create a group, and add a user to a group.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Groups. A list
of the groups in your tenancy appears.
4. Select the user created earlier from the Users drop-down list, and then click Add. The user
now appears in the group.
5. Use the breadcrumb trail to go back to the Groups page and click Create Group.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Policies.
2. Choose a compartment.
3. A list of the policies in the compartment you’re currently viewing appears.
f. Compartment: If you want to attach the policy to a compartment other than the one
you’re viewing, select it from the drop-down list. Remember, where the policy is
attached controls who can later modify or delete it.
Tasks
1. Open the Main Menu and select Identity & Security. Under Identity, click Dynamic
Groups.
c. Name: Enter a unique name for the group. The name must be unique across all groups
in your tenancy, including dynamic groups and user groups.
d. Description: Enter a friendly description.
4. Enter the Matching Rules. Resources that meet the rule criteria are members of the
dynamic group.
− For example, to include all instances that are in a specific compartment, add a rule
with the following syntax:
instance.compartment.id = '<compartment_ocid>'
5. Click Create. The dynamic group now appears in the list of dynamic groups.