Designates a resource directory member as a delegated administrator account of a trusted service.
Operation description
The delegated administrator account can access the structure and members of the resource directory, and perform service-related management operations on behalf of the management account of the resource directory.
Note the following limits:
-
Only some trusted services support delegated administrator accounts. Supported trusted services.
-
Only the management account of a resource directory, or an authorized RAM user or RAM role of the management account, can call this operation.
-
The number of delegated administrator accounts allowed for a trusted service is defined by the trusted service.
The following example designates member 181761095690**** as a delegated administrator account of Cloud Firewall.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
resourcemanager:RegisterDelegatedAdministrator |
create |
*Account
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| AccountId |
string |
Yes |
The ID of the member in the resource directory. |
181761095690**** |
| ServicePrincipal |
string |
Yes |
The identifier of the trusted service. Valid values are listed in the |
cloudfw.aliyuncs.com |
This operation also uses Common parameters.
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
0A45FC8F-54D2-4A65-8338-25E5DEBDA304 |
Examples
Success response
JSON format
{
"RequestId": "0A45FC8F-54D2-4A65-8338-25E5DEBDA304"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 409 | InvalidParameter.ServicePrincipal | The specified ServicePrincipal is invalid. | The specified ServicePrincipal is invalid. |
| 409 | AccountAlreadyRegistered | The specified account is already a delegated administrator for this service. | The specified account is already a delegated administrator for this service. |
| 409 | DelegatedAccountNumberExceeded | The maximum number of delegated administrators for the service principal is exceeded. | The maximum number of delegated administrators for the service principal is exceeded. |
| 409 | CannotRegisterMasterAsDelegatedAdministrator | You attempted to register the enterprise management account as a delegated administrator for the service. You can designate only a member account as a delegated administrator. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.