All Products
Search
Document Center

Identity as a Service:Cloud identity management for Tencent Cloud

Last Updated:Jul 24, 2026

When an enterprise uses multiple Tencent Cloud accounts, it often faces challenges such as scattered accounts and complex permission management. The cloud identity management feature allows you to centrally manage Tencent Cloud accounts and their CAM roles in IDaaS for unified identity governance and access control.

Applicable scope

The Machine Identity Management capability must be activated.

Add a cloud account

Add a Tencent Cloud account to IDaaS, and complete the identity provider and system role configuration in the Tencent Cloud CAM console. This enables IDaaS to automatically discover and synchronize cloud roles under the account.

  1. Log on to the IDaaS management console, and select the target Instance.

  2. Add cloud account information.

    a. In the left-side navigation pane, choose Asset Management > Asset Management > Cloud Identity.

    b. Click Add Cloud Account.

    c. In the Cloud Provider field, select Tencent Cloud, and then configure the following parameters:

    Parameter

    Description

    Site

    Select China Site or International Site based on your Tencent Cloud account site. The default is China Site.

    Account ID

    The primary account ID of the Tencent Cloud account to add. Must be exactly 12 digits.

    Identity Provider Name

    The name of the OIDC identity provider to be created in Tencent Cloud CAM. The prefix idaas-eiam- is fixed by the system; you only need to enter the suffix. The suffix can contain only letters, digits, periods (.), underscores (_), and hyphens (-), and must start and end with a letter or digit. Make sure the name does not conflict with any existing identity provider in CAM. You can check existing names by navigating to the CAM console of the target cloud account, and then clicking Identity Provider > Role SSO.

    d. Click Next.

  3. Configure the unified identity.

    Refer to the on-screen instructions on the IDaaS page, and complete the following configurations in the CAM console of the target Tencent Cloud account:

    a. Configure the identity provider.

    IDaaS displays the following parameters. Enter these parameters in the corresponding fields in the Tencent Cloud CAM console to create an OIDC identity provider:

    Parameter

    Description

    Identity Provider Name

    The name you specified in the previous step (with the idaas-eiam- prefix). Use this name to create an identity provider with the same name in CAM.

    Identity Provider URL

    The OIDC Issuer URL issued by IDaaS. Enter this value in the Provider URL field of the CAM identity provider.

    Client ID

    The Audience identifier for IDaaS. Enter this value in the Audience field of the CAM identity provider.

    Signature Public Key

    The JWKS signing public key automatically obtained by IDaaS. The value is masked on the page. Click the copy button to get the full content, and then enter it in the Signing Key field of the CAM identity provider.

    Note

    The identity provider URL uses the format https://<portal_address>/api/v2/iauths_system/oauth2, where <portal_address> can be found in the User Portal column of the IDaaS management console.

    b. Create a role.

    In the CAM console, create a role. Select the identity provider you created in the previous step, and set the usage condition (enter the Audience value from the IDaaS page in the condition field). For the role name, use the fixed name idaas-eiam-system-role provided on the IDaaS page.

    Note

    The system role name idaas-eiam-system-role cannot be changed. IDaaS validates role configurations based on this name.

    c. Create a custom policy.

    IDaaS displays the system-generated policy content. Copy this content and create a custom policy in the CAM console using the policy generator.

    d. Authorize role permissions.

    In the CAM console, associate the custom policy created in step c with the role created in step b.

  4. Click Start Detection. IDaaS verifies whether the system role configurations are correct.

    • Verification passed: A success message is displayed. Click Confirm to complete the cloud account addition.

    • Verification failed: An error message is displayed. Check and correct the configurations based on the error information, and then click Re-check.

Note

If you exit the page before completing the configuration, go to Asset Management > Asset Management, find the cloud account, and then click Cloud Role Management in the Actions column. Click Details and then Configure System Role to resume the configuration.

After the configuration is complete, you can view the added cloud account on the Asset Management > Asset Management page. Click Cloud Role Management in the Actions column of the target cloud account to view the system role.

Add cloud roles

Add CAM roles under the target cloud account to IDaaS for unified role management and access control.

  1. On the Asset Management > Asset Management > Cloud Identity page, select the managed cloud account, and click Cloud Role Management in the Actions column.

    Note

    If the target cloud account has not been managed, first complete Cloud identity management for Tencent Cloud.

  2. Click Add Cloud Role.

    a. Role Name: Select the CAM role to manage in IDaaS from the drop-down list. The drop-down list automatically retrieves available CAM roles under the Tencent Cloud account.

    b. Trust Policy: Follow the on-screen instructions on the IDaaS page to complete the trust policy configuration for the role in the CAM console of the cloud account.

  3. Click Confirm to complete the cloud role addition.

After the configuration is complete, you can view the added cloud account on the Asset Management > Asset Management > Cloud Identity page. Click Cloud Role Management in the Actions column of the target cloud account to view the added cloud roles.

Note

Follow the principle of least privilege. Configure precise access policies for managed CAM roles. Grant only the minimum permissions required for business operations and avoid overly broad authorization.

Delete cloud roles

Remove a CAM role under the target cloud account from IDaaS management.

  1. On the Asset Management > Asset Management > Cloud Identity page, select the managed cloud account, and click Cloud Role Management in the Actions column.

  2. In the cloud role list, find the target cloud role and click the toggle switch in the Cloud Role Status column to disable the cloud role.

    Note

    Disabling a cloud role prevents applications and users from using the corresponding role. Make sure you understand the business impact before proceeding.

  3. Click Delete in the Actions column.

Delete a cloud account

Remove a Tencent Cloud account from IDaaS management.

Important

Before you delete a cloud account, you must delete all user-created cloud roles under the account first.

On the Asset Management > Asset Management > Cloud Identity page, find the target cloud account, and click Delete in the Actions column.