IBM Cloud Docs
Why can't I delete access management tags?

Why can't I delete access management tags?

If you can't delete an access management tag within an IBM Cloud® account that you're not the owner of, you might need to check the type of access you're assigned. Or, the tag might be attached to a resource.

  • You can't delete access management tags in an account of which you are a member.
  • You have the permission, but still unable to delete an access management tag.

The action might be blocked by one of the following reasons:

  • You might not be assigned the appropriate access to complete the action. You must have the Administrator role on all Account management services.
  • The access management tag you're trying to delete is still attached to an active or a reclaimed resource.

Complete the following steps to check your level of access. If you need to request access, contact the account owner.

Go to Manage > Access (IAM) in the IBM Cloud console, and select your name on the Users page.

  • To view IAM access policies that are assigned to you, select Access and view the Access policies table.
  • To determine what access you have through the access groups you are assigned, select Access and view the Access groups table. Check the access policies for each of the access groups.

To view what actions are mapped to each role, click the numbers listed next to each role.

Before you try to delete an access management tag, make sure it's not attached to any of your resources.

  • Filter by tag name on your resource list. If you don't have a viewer permission for all existing resources, contact the account owner to verify.
  • Use the ibmcloud resource reclamation command in the IBM Cloud® CLI to list out resources in reclamation state and delete the resource that had the tag you were trying to delete. For more information, see Using resource reclamations.

When you delete an access management tag from the account, any associated IAM policies are also deleted with it.