Menghapus izin akses pada akun di direktori sumber daya.
Deskripsi operasi
When you call this operation, an asynchronous task is created. You can call the GetTask operation to query the progress of the task based on the value of the TaskId response parameter.
This topic provides an example on how to remove the access permissions on the account 114240524784**** in the resource directory from the CloudSSO user u-00q8wbq42wiltcrk****. The access permissions are assigned by using the access configuration ac-00jhtfl8thteu6uj****.
Coba sekarang
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cloudsso:DeleteAccessAssignment |
delete |
*AccessConfiguration
User
Group
*Account
|
None | None |
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| DirectoryId |
string |
Yes |
ID direktori. |
d-00fc2p61**** |
| AccessConfigurationId |
string |
Yes |
ID konfigurasi akses. |
ac-00jhtfl8thteu6uj**** |
| TargetType |
string |
Yes |
Tipe objek Tugas. Tetapkan nilai ke RD-Account, yang menentukan akun di direktori sumber daya. |
RD-Account |
| TargetId |
string |
Yes |
ID objek Tugas. |
114240524784**** |
| PrincipalType |
string |
Yes |
Tipe identitas SSO Cloud. Nilai valid:
|
User |
| PrincipalId |
string |
Yes |
ID identitas SSO Cloud.
|
u-00q8wbq42wiltcrk**** |
| DeprovisionStrategy |
string |
No |
Apakah akan membatalkan penyediaan konfigurasi akses ketika Anda menghapus izin akses dari identitas SSO Cloud. Konfigurasi akses digunakan untuk menetapkan izin akses, dan identitas tersebut adalah satu-satunya yang menggunakan konfigurasi akses dan terkait dengan akun. Nilai valid:
|
None |
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| Task |
object |
The task information. |
|
| Status |
string |
The task status. Valid values:
|
InProgress |
| TaskId |
string |
The task ID. |
t-shfqw1u1edszvxw5**** |
| PrincipalId |
string |
The ID of the CloudSSO identity. |
u-00q8wbq42wiltcrk**** |
| TargetPath |
string |
The path ID of the task object in the resource directory. |
rd-3G****/r-Wm****/114240524784**** |
| PrincipalName |
string |
The name of the CloudSSO identity. |
Alice |
| TargetName |
string |
The name of the task object. |
dev-test |
| TargetId |
string |
The ID of the task object. |
114240524784**** |
| AccessConfigurationName |
string |
The name of the access configuration. |
ECS-Admin |
| TargetPathName |
string |
The path name of the task object in the resource directory. |
rd-3G****/root/dev-test |
| TaskType |
string |
The task type. The value is fixed as DeleteAccessAssignment, which indicates that access permissions on an account in your resource directory are removed. |
DeleteAccessAssignment |
| TargetType |
string |
The type of the task object. The value is fixed as RD-Account, which indicates the accounts in the resource directory. |
RD-Account |
| AccessConfigurationId |
string |
The ID of the access configuration. |
ac-00jhtfl8thteu6uj**** |
| PrincipalType |
string |
The type of the CloudSSO identity. Valid values:
|
User |
| RequestId |
string |
The request ID. |
5C9D0CF4-5CE8-5CE6-932A-826EF4ADD007 |
Contoh
Respons sukses
JSONformat
{
"Task": {
"Status": "InProgress",
"TaskId": "t-shfqw1u1edszvxw5****",
"PrincipalId": "u-00q8wbq42wiltcrk****",
"TargetPath": "rd-3G****/r-Wm****/114240524784****",
"PrincipalName": "Alice",
"TargetName": "dev-test",
"TargetId": "114240524784****",
"AccessConfigurationName": "ECS-Admin",
"TargetPathName": "rd-3G****/root/dev-test",
"TaskType": "DeleteAccessAssignment",
"TargetType": "RD-Account",
"AccessConfigurationId": "ac-00jhtfl8thteu6uj****",
"PrincipalType": "User"
},
"RequestId": "5C9D0CF4-5CE8-5CE6-932A-826EF4ADD007"
}
Kode kesalahan
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.