Skip to content

Commit d6b07ba

Browse files
feat(iam): fixes
1 parent 5003fb3 commit d6b07ba

File tree

5 files changed

+44
-36
lines changed

5 files changed

+44
-36
lines changed

pages/account/how-to/use-2fa.mdx

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,10 @@ Download the app of your choice and install it onto your smartphone.
3232

3333
## How to enable MFA
3434

35-
1. Access the [Security](https://console.scaleway.com/account/security) tab of your **User Account** page.
36-
Alternatively, click your Organization name on the top-right corner of the console navigation menu, click **Profile**, then **Security**.
35+
1. Click your Organization name on the top-right corner of the console navigation menu, click **Profile**, then **Security**.
36+
<Message type="important">
37+
If you are logged in as an [IAM member](/iam/concepts/#member), Click **Profile**, then **Credentials** and scroll down to the **Multifactor authentication** section.
38+
</Message>
3739
2. Click **Enable MFA**, in the **Multifactor authentication** section. A pop-up displays.
3840
3. Enter the code shown on the pop-up into your MFA app, or scan the QR code into your app.
3941
Your app sets up MFA for your Scaleway account and displays a 6-digit code.

pages/iam/how-to/comply-with-sec-requirements-member.mdx

Lines changed: 16 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -17,15 +17,15 @@ Upon your [first login as a Member](/iam/how-to/log-in-as-a-member), you must co
1717

1818
## How to check the security requirements
1919

20-
When you log in for the first time, a security checklist displays in your Scaleway console.
21-
22-
<Lightbox src="scaleway-iam-member-sec-req.webp" alt="screenshot of the scaleway console showing a checklist of the few quick steps to follow until you can explore the Scaleway console. 1. Update password - You are required to update your password to stay connected to this Organization. A message box indicated that there is 1 day left to update the password. It warns that once this grace period is up, you will be locked out of the Organization until an administrator unlocks your account. A button prompts to update the password. "/>
23-
24-
Currently, the mandatory security requirements include:
20+
You Organization administrators may require you to perform two different security actions:
2521

2622
- [Updating your password](#how-to-update-a-password)
2723
- [Setting up MFA](#how-to-set-up-mfa-as-a-member)
2824

25+
If one of these requirements is enforced in your Organization, a security checklist will display in your Scaleway console when you log in for the first time,
26+
27+
<Lightbox src="scaleway-iam-member-sec-req.webp" alt="screenshot of the scaleway console showing a checklist of the few quick steps to follow until you can explore the Scaleway console. 1. Update password - You are required to update your password to stay connected to this Organization. A message box indicated that there is 1 day left to update the password. It warns that once this grace period is up, you will be locked out of the Organization until an administrator unlocks your account. A button prompts to update the password. "/>
28+
2929
### Grace period
3030

3131
New IAM Members have a [grace period](/iam/concepts/#grace-period) available to comply with security requirements. The grace period is defined by the Organization's administrator or is set to default (7 days).
@@ -46,7 +46,11 @@ This means that if you fail to login five times, you will be blocked from your O
4646

4747
Passwords are not required for a first Member login.
4848

49-
However, even if your Organization administrator provides you with a password or you log in using a code, you must update your password after your first login.
49+
However, if password renewal is enforced in your Organization, you must update your password after your first login.
50+
51+
<Message type="note">
52+
Your Organization's administrator may provide you with a password for your first login. If password renewal is enforced in your Organization, you still need to update your password.
53+
</Message>
5054

5155
1. Click **Update password** in your security requirements **Checklist** in the Scaleway console. A pop-up appears.
5256
<Message type="note">
@@ -55,15 +59,15 @@ However, even if your Organization administrator provides you with a password or
5559
2. Define a new password in the box.
5660
3. (Optional) Check the box if you want to send the password to your email.
5761
<Message type="tip">
58-
Make sure you copy and securely store the password, as it will only be shown once. If you lose access to your password, you must renew it.
62+
Make sure you copy and securely store the password, as it will only be shown once. If you lose access to your password, you must renew it again. Refer to the [How to manage members](/iam/how-to/manage-members#how-to-edit-a-members-information) documentation to learn how to renew your password after first renewal.
5963
</Message>
6064

6165
If all security requirements are met, you will be redirected to the Organization dashboard. If not, follow the steps of the [next section](#how-to-set-up-mfa-as-a-member) to complete the checklist.
6266

6367
## How to set up MFA as a Member
6468

65-
66-
67-
68-
69-
69+
1. Click **Identity and Access Management (IAM)** from the top-right of your [Organization Dashboard](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
70+
2. Click your username. Alternatively, click <Icon name="more" /> next to the user, and select **Overview**. Either way, you are taken to the user's **Overview** tab.
71+
3. Go to the **Credentials** tab.
72+
4. Scroll down to the **Multifactor authentication** section.
73+
5. Follow the steps indicated in the [How to use MFA](/account/how-to/use-2fa) documentation page.

pages/iam/how-to/enforce-security-requirements-members.mdx

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,15 @@ If [Multifactor Authentication (MFA) is enabled](/account/how-to/use-2fa) for a
3737
</Message>
3838
6. Type **DISABLE** in the box and click **Confirm**.
3939

40+
## How to enforce MFA for a member
41+
42+
You can enforce MFA for all users in your Organization, including members.
43+
44+
<Message type="tip">
45+
Refer to the [How to enforce MFA](/organizations-and-projects/how-to/enforce-mfa) documentation page for more information.
46+
</Message>
47+
48+
4049
## How to enforce password renewal
4150

4251
1. Click the **Security** tab of the [Organization Dashboard](https://console.scaleway.com/organization).
@@ -72,9 +81,4 @@ From their first login, members have a default grace period of seven days to com
7281

7382
Currently, a default number of a maximum 5 login attempts is set up for your Organization automatically.
7483

75-
## How to enforce MFA for a member
76-
77-
You can enforce MFA for all users in your Organization, including members.
78-
79-
Refer to the [How to enforce MFA](/pages/organizations-and-projects/how-to/enforce-mfa) documentation page for more information.
8084

pages/iam/how-to/manage-members.mdx

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ The Member is locked and their name is displayed in red and their status is mark
5555
If a Member is locked you can unlock them anytime as an Owner or user with IAM Manager permissions. Their name is displayed in red and their status is marked as `Locked` in the IAM users list.
5656

5757
<Message type="important">
58-
If a Member fails to [comply with security requirements](/iam/how-to/log-in-as-a-member#how-to-comply-with-security-requirements) by the end of the [grace period](/organizations-and-projects/concepts), they are automatically locked and are not able to connect to the Organization until they are manually unlocked.
58+
If a Member fails to [comply with security requirements](/iam/how-to/log-in-as-a-member#how-to-comply-with-security-requirements) by the end of the [grace period](/iam/concepts#grace-period), they are automatically locked and are not able to connect to the Organization until they are manually unlocked.
5959
</Message>
6060

6161
1. Click **Identity and Access Management (IAM)** on the top-right corner of your [Organization Dashboard](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
@@ -73,6 +73,10 @@ The Member is unlocked.
7373

7474
You can edit a Member's username, email address, and password.
7575

76+
<Message type="note">
77+
Follow the procedure below to edit your own Member information.
78+
</Message>
79+
7680
1. Click **Identity and Access Management (IAM)** on the top-right corner of your [Organization Dashboard](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
7781
2. Click the name of the Member you want to delete. Alternatively, click <Icon name="more" /> next to the Member, and select **Overview**. Either way, you are taken to the user's **Overview** tab.
7882
3. Click the **Credentials** tab.
@@ -89,18 +93,19 @@ The updated information appears in the credentials tab.
8993

9094
For the increased security of your Organization, you can enforce different security measures for your IAM Members.
9195

92-
Refer to the dedicated [How to enforce security Members for Members](/iam/how-to/enforce-security-requirements-members/) documentation page to find how to:
96+
Refer to the dedicated [How to enforce security for Members](/iam/how-to/enforce-security-requirements-members/) documentation page to find how to:
9397

9498
- [How to disable a Member's MFA](/iam/how-to/enforce-security-requirements-members/#how-to-disable-a-members-mfa)
9599
- [How to enforce password renewal](/iam/how-to/enforce-security-requirements-members/#how-to-enforce-password-renewal)
96100
- [How to stop enforcing password renewal](/iam/how-to/enforce-security-requirements-members/#how-to-stop-enforcing-password-renewal)
97101
- [How to edit the grace period of your Organization](/iam/how-to/enforce-security-requirements-members/#how-to-edit-the-grace-period-of-your-organization)
98102
- [How to set a maximum number of login attempts](/iam/how-to/enforce-security-requirements-members/#how-to-set-a-maximum-number-of-login-attempts)
99103

104+
100105
## How to delete a Member
101106

102107
<Message type="important">
103-
A Member can delete their own account. The procedure is the same as described below.
108+
A Member can delete their own account. The procedure is the same as described below. When a Member deletes themselves, they are automatically disconnected from the Scaleway console.
104109
</Message>
105110

106111
1. Click **Identity and Access Management (IAM)** on the top-right corner of your [Organization Dashboard](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
@@ -117,4 +122,3 @@ Refer to the dedicated [How to enforce security Members for Members](/iam/how-to
117122

118123
The Member is deleted. If you wish to check the Member's previous logs from this point on, keep in mind that they will appear as "Deleted user" in the IAM logs. The user ID remains visible.
119124

120-

pages/iam/quickstart.mdx

Lines changed: 7 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -26,23 +26,20 @@ Read our dedicated page for a [general overview of IAM](/iam/reference-content/o
2626
Invite other users to be able to give them access to your Organization. You will be able to define the exact level of access to give by creating a [policy](#how-to-give-permissions-to-users-and-applications-via-policies) for them later.
2727

2828
1. Click **Identity and Access Management (IAM)** from the top-right of your [**Organization Dashboard**](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
29-
<Lightbox src="scaleway-iam-users-dashboard.webp" alt="" />
30-
2. Click **+ Add user**. The following screen displays:
31-
<Lightbox src="scaleway-iam-invite-user.webp" alt="" />
32-
3. Enter the email address of the person you want to invite. If you want to invite more than one user, enter multiple email addresses separated by commas. Optionally, you can also select a [group](/iam/concepts/#group) to add the user to.
33-
4. Click **Invite** to send the invitation.
29+
2. Click **+ Add user**. A pop-up displays prompting you to choose between creating a **Member** or adding a **Guest**.
30+
3. Select **Guest** and click **Continue**.
31+
4. Enter the email address of the person you want to invite. If you want to invite more than one user, enter multiple email addresses separated by commas. Optionally, you can also select a [group](/iam/concepts/#group) to add the user to and add one or more tags.
32+
5. Click **Invite** to send the invitation.
3433
The user receives an email inviting them to accept your invitation. If they do not already have a Scaleway account, they will be prompted to [create one](/account/how-to/create-an-account/) first.
35-
5. The user will appear in the list of your Organization's users once they have accepted the invitation.
34+
6. The user will appear in the list of your Organization's users once they have accepted the invitation.
3635

3736
## How to create an application
3837

3938
IAM applications are non-human users in an Organization, enabling you to give programmatic access to resources.
4039

4140
1. Click **Identity and Access Management (IAM)** from the top-right of your [**Organization Dashboard**](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
4241
2. Click the **Applications** tab. A list of the Organization's existing IAM applications displays.
43-
<Lightbox src="scaleway-iam-applications.webp" alt="" />
4442
3. Click **Create application**. The creation wizard displays:
45-
<Lightbox src="scaleway-iam-create-app.webp" alt="" />
4643
4. Complete the steps of the creation wizard:
4744
- Enter a name for the application, or use the auto-generated name suggested for you,
4845
- Enter a description (optional),
@@ -56,10 +53,8 @@ IAM applications are non-human users in an Organization, enabling you to give pr
5653

5754
Users you have invited to your Organization, and applications you have created, have no rights or permissions until you attach [policies](/iam/reference-content/policy/) to them, as described below.
5855
1. Click **Identity and Access Management (IAM)** from the top-right of your [**Organization Dashboard**](https://console.scaleway.com/organization) in the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
59-
2. Click the **Policies** tab. A list of the Organization's existing policies displays:
60-
<Lightbox src="scaleway-iam-policies.webp" alt="" />
61-
3. Click **Create policy**. The creation wizard displays:
62-
<Lightbox src="scaleway-iam-create-policy-1.webp" alt="" />
56+
2. Click the **Policies** tab. A list of the Organization's existing policies displays.
57+
3. Click **Create policy**. The creation wizard displays.
6358
4. Complete the steps on the first page of the creation wizard:
6459
- Enter a **name** for the policy,
6560
- Enter a **description** (optional),
@@ -68,7 +63,6 @@ Users you have invited to your Organization, and applications you have created,
6863
You can choose to create a policy without a principal for now, and attach the principal later. Be aware that the policy will have no effect until a principal is attached. A policy can only be attached to one principal at a time.
6964
</Message>
7065
5. Click **Add rules** to progress to the next part of the policy creation wizard.
71-
<Lightbox src="scaleway-iam-create-policy-2.webp" alt="" />
7266
<Message type="tip">
7367
Rules define the actions that the attached principal will be able to carry out within the Organization. When creating a rule, you first set the **scope** of the rule, and then select the **permission sets** to apply within the scope. See our dedicated documentation for more help with [policies, rules, scopes and permission sets](/iam/reference-content/policy/).
7468
</Message>

0 commit comments

Comments
 (0)