Today we are announcing a brand-new way to manage access to IBM Cloud resources called tag-based access management.

This new access management capability allows authorized users to create IAM policies based on a new object called the access management tag. This new type of tag can be added to IAM-enabled IBM Cloud resources, making these resources objects of tag-based IAM policies.

How does tag-based access management work?

Tag-based access management allows an administrator of an IAM-enabled resource to create an access policy based on existing access management tags. An access policy that contains access management tags provides administrators the ability to grant or revoke access to a resource by attaching or detaching the access management tag to the resource. Using access management tags may reduce the number of access policies needed within an account while also providing a simplified way to grant access to a heterogeneous group of resources.

Start using tag-based access management

To get started, select a resource that you want to tag from the Resource List. You can add an access management tag by selecting Add tags from the actions menu for the resource. Access management tags must follow “key:value” format:

Once you’ve tagged the appropriate resources with the new access management tag, the access policy creation step is very similar to what it has been previously. However, instead of creating an access policy targeting a specific resource or resource group, you will create the access policy with the newly created access management tag as the target.

Begin by selecting All Identity and Access enabled services from the dropdown, as seen below. Then, you’ll use the new Services based on attributes button and select Access management tags. All you have to do from there is pick your access management tag from the dropdown and select one or more roles for the access policy. Finish by creating the access policy, and you’ve successfully begun to use the new tag-based access management system:

One example of a useful way to use the new access management tag is to provide access to a testing environment in an account. An account administrator can tag all resources related to a specific testing environment with a unique access management tag. Then, they can create a tag-based access policy for an access group or a developer to gain access to those resources. If the account administrator needs to add or remove resources from the testing environment, it is as simple as adding or removing the access management tag from a resource.   

Learn more

The release of the access management tag and our brand-new tag-based access management paradigm represents a huge step forward for IBM Cloud and our customers. To learn more, see the documentation.

We are very excited for our users to enjoy this new, simplified method of access management. We also look forward to any feedback, as always. Thanks for reading, now get to tagging!

Categories

More from Cloud

IBM Tech Now: October 2, 2023

< 1 min read - ​Welcome IBM Tech Now, our video web series featuring the latest and greatest news and announcements in the world of technology. Make sure you subscribe to our YouTube channel to be notified every time a new IBM Tech Now video is published. IBM Tech Now: Episode 86 On this episode, we're covering the following topics: AI on IBM Z IBM Maximo Application Suite 8.11 IBM NS1 Connect Stay plugged in You can check out the IBM Blog Announcements for a…

IBM Cloud inactive identities: Ideas for automated processing

4 min read - Regular cleanup is part of all account administration and security best practices, not just for cloud environments. In our blog post on identifying inactive identities, we looked at the APIs offered by IBM Cloud Identity and Access Management (IAM) and how to utilize them to obtain details on IAM identities and API keys. Some readers provided feedback and asked on how to proceed and act on identified inactive identities. In response, we are going lay out possible steps to take.…

IBM Cloud VMware as a Service introduces multitenant as a new, cost-efficient consumption model

4 min read - Businesses often struggle with ongoing operational needs like monitoring, patching and maintenance of their VMware infrastructure or the added concerns over capacity management. At the same time, cost efficiency and control are very important. Not all workloads have identical needs and different business applications have variable requirements. For example, production applications and regulated workloads may require strong isolation, but development/testing, training environments, disaster recovery sites or other applications may have lower availability requirements or they can be ephemeral in nature,…

IBM accelerates enterprise AI for clients with new capabilities on IBM Z

5 min read - Today, we are excited to unveil a new suite of AI offerings for IBM Z that are designed to help clients improve business outcomes by speeding the implementation of enterprise AI on IBM Z across a wide variety of use cases and industries. We are bringing artificial intelligence (AI) to emerging use cases that our clients (like Swiss insurance provider La Mobilière) have begun exploring, such as enhancing the accuracy of insurance policy recommendations, increasing the accuracy and timeliness of…