An access configuration is a configuration template that is used by CloudSSO users to access the accounts in a resource directory. The template contains permission configurations. You can use this template to assign access permissions on the accounts in your resource directory to CloudSSO users. This topic describes how to create an access configuration.
Procedure
Log on to the CloudSSO console.
In the left-side navigation pane, click Access Configuration Management.
On the Access Configuration Management page, click Create Access Configuration.
In the Create Access Configuration panel, configure the parameters and click OK.
Access Configuration Name: required. The name of the access configuration, which must be unique within the directory.
Session Duration: optional. The duration of a session in which a CloudSSO user accesses an account in your resource directory by using the access configuration. Unit: seconds. Valid values: 900 to 43200 (15 minutes to 12 hours). Default value: 3600 (1 hour).
Relay State: optional. The initial web page displayed after a CloudSSO user uses the access configuration to access an account in your resource directory. The web page must be a page of the Alibaba Cloud Management Console. By default, this parameter is empty, which indicates that the initial web page is the homepage of the Alibaba Cloud Management Console.
Description: optional. The description of the access configuration.
Configure system policies.
Use system policies
Select Use System Policy.
Select the required system policies.
Click Bind and Continue.
Click Next.
Do not use system policies
Select Not Use System Policy.
Click Continue.
Configure inline policies.
Click Create Inline Policy.
Enter a name for the inline policy and click OK.
Enter the content of the inline policy and click Update Inline Policy.
The Resource Access Management (RAM) policy syntax is reused for inline policies. For more information, see Policy elements.
Click Close.
What to do next
After you create the access configuration, you can use it to assign access permissions on the accounts in your resource directory to CloudSSO users. This way, the ClousSSO users can access the resources within the accounts. For more information, see Assign access permissions on the accounts in a resource directory.