Managing identity and access

You can use the Identity and access management (IAM) panel to manage identities, identity providers, and keys in R‑Cloud.

Prerequisite

You must have the Administrator role assigned.

Depending on what you want to do, see one of the following topics:

Managing identities

The R‑Cloud identity management system provides security mechanisms to help prevent unauthorized identities (users or service accounts) from accessing protected data. Only identities that are given specific rights have access to the data protection environment. You can add the following identity types:

  • Local user is authenticated by R‑Cloud.

  • SSO user is authenticated by one of the identity providers that are configured in R‑Cloud. For details, see Managing identity providers.

  • Service account is an account that accesses the R‑Cloud REST API. A service account has no password and authenticates only by using keys. For details, see Managing keys.

Identities can be managed in the context of the currently selected subscription or protection set. Therefore, the scope of tasks that you can perform depends on the selected user interface context.

Depending on what you want to do, see one of the following topics:

I want to... User interface context Instructions
Add an identity to R‑Cloud. Subscription or Protection set Adding an identity
Manage keys. Subscription or Protection set Managing keys
Assign or unassign a role, or request a password reset for a local user. Subscription or Protection set

Editing an identity

Note  For details about roles, see R‑Cloud roles.

Activate or deactivate a user. Subscription Activating or deactivating a user
Remove an identity from a protection set. Protection set Removing an identity from a protection set
Remove an identity from R‑Cloud. Subscription Removing an identity from R‑Cloud

R‑Cloud roles

A role determines the scope of actions that can be performed in the R‑Cloud data protection environment by a specific identity. This means that access to data and information within the data protection environment is limited based on the assigned role. You can assign or unassign these roles to define what actions can be performed by each identity.

One or more of the following roles can be assigned to an identity:

Role Allowed actions
Administrator Perform all actions in the data protection environment.
Backup Operator

Define policies, manage targets, assign data mover configurations, back up SaaS applications, applications, instances, and buckets, and view the same information as Viewer.

Restore Operator

Restore SaaS applications, applications, instances, and buckets, and view the same information as Viewer.

Viewer View information about SaaS applications, applications, instances, buckets, policies, targets, tasks, events, reports, cloud accounts, and protection sets in the data protection environment.

For instructions on how to assign or unassign a role, see Assigning or unassigning a role.

Adding an identity

Considerations

  • Local users must set their password at first sign-in.

  • A service account requires a key to authenticate. You can create one or more keys for the service account at any time. For instructions, see Creating a key.

  • You can add a local or an SSO user to one or more protection sets, and a service account to only one protection set.

  • The service account name can contain only lowercase letters, digits, and hyphens. It must begin with a letter, and it cannot be longer than 128 characters.

Procedure

  1. In the IAM panel, click New New Identity.

  2. From the Identity Type drop-down menu, select the type of identity that you want to add:

    • Local User

    • SSO User

    • Service Account

  3. Depending on the selected identity type, do one of the following:

    • If you are adding a local or SSO user, enter the email address of the user that you want to add in lowercase letters.

    • If you are adding a service account, enter its name.

  4. Only if you are adding an identity in the Subscription context. Select one of the following options:

    • Assign to Subscription

      Assign the identity to the currently selected subscription.

    • Assign to Protection Set

      From the list of protection sets, select one or more protection sets to which you want to assign the identity.

      Tip  You can search for a protection set by entering its name in the Search field and then pressing Enter.

  5. From the Role drop-down menu, select the role for the identity. You can select more than one role if needed. For details on roles, see R‑Cloud roles.

  6. Click Save.

Managing keys

To allow service accounts to access the R‑Cloud REST API, you must create keys.

Consideration

In the Protection set context, you can manage keys only for the service accounts that belong to the currently selected protection set.

Creating a key

Considerations

  • For each service account, the name of the created key must be unique.

  • You can create up to 10 keys per service account. The expired keys count toward this limit.

Procedure

  1. In the IAM panel, select the service account for which you want to create a key.

  2. Click  Keys.

  3. Click New New.

  4. Enter a name for the key.

  5. Optional. From the Key Expiration drop-down menu, select the expiration period, or select Custom and specify a custom expiration date. If you do not set the expiration date, the key does not expire.

  6. Click Generate. The new key is displayed. You can copy the key to the clipboard by clicking  Copy to Clipboard.

    Important  For security reasons, the key will never be displayed again, so make sure to write it down and keep it safe. Your key can be used to access your data, therefore, treat it like a password.

  7. Click Finish.

The key is added to the list of keys. For each key, you can see the following details:

  • The name of the key.

  • The automatically created unique key identifier.

  • The time when the key was created.

  • The time when the key was last used by the service account.

  • Key expiration status. For the unexpired keys, the expiration time is displayed.

You can later revoke the added keys. For instructions, see Revoking a key.

Using a key

Procedure

  1. To exchange the generated key for a bearer token, perform the following call from your terminal or script (replace <key> with the generated key value): 

    curl 'https://authentication.r-cloud.hycu.com/api/v2/authentication/token' -u '<key>' -d grant_type=client_credentials

    The call returns a response in JSON format, for example: 

    {
        "access_token": "eyJhbGciOiJSUzI...",
        "token_type": "Bearer",
        "expires_in": 3599
    }
  2. Use the returned token as the Authorization header value for the R‑Cloud API calls that follow.

    To see the available R‑Cloud API calls, click Help Help in the toolbar, and then select REST API Explorer.

Revoking a key

Recommendation

It is recommended to revoke the keys that you no longer need.

Procedure

  1. In the IAM panel, from the list of available identities, select the service account for which you want revoke the key.

  2. Click  Keys.

  3. Select the key that you want to revoke, and then click Remove Revoke.

  4. Click Revoke to confirm that you want to revoke the key.

    Note  A session that was already established by using a key that was later revoked remains active for up to 60 minutes.

  5. The key is immediately revoked and removed from the list of keys.

Editing an identity

By editing an identity, you can assign or unassign a role, or request a password reset for a local user. For details about roles, see R‑Cloud roles.

Depending on what you want to do, see one of the following topics:

Assigning or unassigning a role

Considerations

  • At least one identity with the Administrator role assigned in the Subscription context must exist for each subscription.

  • The roles that are assigned in the Subscription context are inherited to all protection sets under the currently selected subscription. The roles that are assigned in the Protection set context apply for the currently selected protection set.

  • If you plan to remove your own Administrator role, keep in mind that you will not be able to change your role back to Administrator yourself.

Procedure

  1. In the IAM panel, from the list of available identities, select the identity for which you want to change the role, and then click Edit Edit.

  2. From the drop-down list, select the role that you want to assign or unassign.

    If you want to assign or unassign more than one role, you can select or deselect the roles individually, or you can click Select all to select all roles at once.

  3. Click Save.

Requesting a password reset

If the passwords of local users should be changed due to company policy requirements or safety reasons, you can send the user a password reset request.

Procedure

  1. In the IAM panel, from the list of available identities, select the local or SSO user that should reset their password, and then click Edit Edit.

  2. Click Request Password Reset.

  3. Click Request Password Reset to confirm that you want to request a password reset for this user.

The user will receive an email containing the password verification code that allows them to reset the password the next time they sign in to R‑Cloud.

Activating or deactivating a user

Considerations

  • You can activate or deactivate a user only in the Subscription context.

  • You cannot deactivate a service account. To prevent a service account from accessing R‑Cloud, revoke its keys or remove it.

  • When you deactivate a user, they can no longer perform any actions. The inactive user is preserved, including all the backed-up data.

Procedure

  1. In the IAM panel, from the list of available identities, select the user whose status you want to change.

  2. Depending on the status of the user, do one of the following:

    • Click Deactivate Deactivate, and then click Deactivate to confirm that you want to deactivate the user.

    • Click Activate Activate, and then click Activate to confirm that you want to activate the user.

Removing an identity from a protection set

Considerations

  • You cannot remove an identity that has an inherited role from the Subscription context.

  • If an identity is only a member of the currently selected protection set, removing the identity from the protection set also removes it from R‑Cloud.

Procedure

  1. In the IAM panel, from the list of available identities, select the one that you want to remove from the currently selected protection set.

    Tip  You can also search for an identity by entering its name in the Search field.

  2. Click Remove Remove.

  3. Click Remove to confirm that you want to remove the identity from the protection set.

Removing an identity from R‑Cloud

Considerations

  • You cannot remove yourself from R‑Cloud.

  • Any upcoming data protection tasks related to the identity that you remove will be automatically assigned to you.

  • Removing a service account is permanent. All of its keys are revoked, and the name becomes available again.

Procedure

  1. In the IAM panel, from the list of available identities, select the one that you want to remove from R‑Cloud.

    Tip  You can also search for an identity by entering its name in the Search field.

  2. Click Remove Remove.

  3. Click Remove to confirm that you want to remove the identity from R‑Cloud.

Managing identity providers

You can integrate R‑Cloud with identity providers that support the OpenID Connect authentication protocol, such as Google, Microsoft, and Okta. This gives the SSO users the possibility to securely sign in to R‑Cloud by using these identity providers, without the need to maintain dedicated credentials for R‑Cloud.

Recommendation

In addition to the SSO users that will be authenticated by identity providers, it is recommended that your data protection environment contains at least one user that is authenticated by R‑Cloud. This ensures that R‑Cloud can be accessed if the identity provider is unavailable for any reason.

Adding an identity provider to R‑Cloud

Prerequisites

R‑Cloud must be registered as a web application within the identity provider that you plan to add to R‑Cloud. When registering R‑Cloud, make sure the following is done:

  • For Microsoft: In Azure, R‑Cloud must be given access permissions to the Microsoft Graph API with delegated permissions for User.Read.

  • For Okta: In Okta, you must select Authorization Code under Client acting on behalf of a user as the grant type.

For instructions on how to register an application, see the respective identity provider documentation.

Recommendation

For Okta: By following the procedure described in this topic, you can enable the SSO users to sign in to R‑Cloud with the Okta identity provider (IdP). However, it is recommended that you configure single sign-on (SSO) with the Okta Integration Network (OIN) application. For instructions, see Configuring R‑Cloud SSO with Okta.

Procedure

  1. In the Identity Providers dialog box, click New New.

  2. Enter a name for the identity provider. The name that you specify must contain only lowercase letters and hyphens, it must begin and end with a lowercase letter, and it may not be longer than 63 characters.

  3. From the Type drop-down menu, select one of the following types of identity providers, and then follow the instructions:

    Identity provider type Instructions
    Google
    1. In the Client ID field, enter the application ID that is generated by the identity provider.

    2. In the Client Secret field, enter the application secret that is associated with the client ID and generated by the identity provider.

    Microsoft
    1. In the Client ID field, enter the application ID that is generated by the identity provider.

    2. In the Client Secret field, enter the application secret that is associated with the client ID and generated by the identity provider.

    3. In the Issuer field, enter the URL of the issuer of the identity provider.

    Okta
    OIDC
    Cognito
  4. Click  Copy to Clipboard to copy the redirect URL that you need to enter when you create the application integration with R‑Cloud.

  5. Click Save.
  6. Configure your identity provider and enter the redirect URL that you copied. For details on the required format, see the respective identity provider documentation.

You can later do the following:

  • Edit information about any of the existing identity providers by clicking Edit Edit and making the required modifications.

  • Delete any of the existing identity providers by clicking Delete Delete.