As funções da gestão de identidade e de acesso (IAM) determinam como pode usar a API Managed Service for Microsoft Active Directory (Managed Microsoft AD). Segue-se uma lista de cada função do IAM disponível para o Microsoft AD gerido e os métodos disponíveis para cada função.
Além disso, as contas de serviço têm de ter a autorização servicemanagement.services.bind
para ver e ativar o Microsoft AD gerido. Saiba mais sobre as funções e as autorizações de gestão de serviços.
| Role | Permissions |
|---|---|
Google Cloud Managed Identities Admin( Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level. |
|
Google Cloud Managed Identities Backup Admin( Full access to Google Cloud Managed Identities Backup and related resources. Intended to be granted on a project-level |
|
Google Cloud Managed Identities Backup Viewer( Read-only access to Google Cloud Managed Identities Backup and related resources. |
|
Google Cloud Managed Identities Domain Admin( Read-Update-Delete to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a resource (domain) level. |
|
Google Cloud Managed Identities Domain Join Beta( Access to domain join VMs with Cloud AD |
|
Managedidentities Editor( Editor role for managedidentities |
|
Google Cloud Managed Identities Peering Admin( Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level |
|
Google Cloud Managed Identities Peering Viewer( Read-only access to Google Cloud Managed Identities Peering and related resources. |
|
Cloud Managed Identities Service Agent( Gives Managed Identities service account access to managed resources. |
|
Google Cloud Managed Identities Viewer( Read-only access to Google Cloud Managed Identities Domains and related resources. |
|
Para mais informações sobre as funções de IAM, consulte o artigo Compreender as funções.