> ## Documentation Index
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Identity and Access Management docs

Secure your IBM Cloud resources with comprehensive identity and access management. Control who has access to your resources, manage authentication methods, implement context-based restrictions, and ensure compliance with enterprise security requirements.

## Get started

- [Getting started with IBM Cloud IAM](https://cloud.ibm.com/docs/iam?topic=iam-iamoverview&format=markdown)
- How IAM works
   - [Identity types for users, services, and workloads](https://cloud.ibm.com/docs/iam?topic=iam-identity-overview&format=markdown)
   - [IAM access concepts](https://cloud.ibm.com/docs/iam?topic=iam-access-management-overview&format=markdown)
   - [IAM access policies for resource-level permissions](https://cloud.ibm.com/docs/iam?topic=iam-iamusermanpol&format=markdown)
   - [Platform and service access roles for permissions](https://cloud.ibm.com/docs/iam?topic=iam-userroles&format=markdown)
   - [Implementing least privilege access](https://cloud.ibm.com/docs/iam?topic=iam-least-privilege&format=markdown)
   - [Mapping IBM Cloud IAM concepts to other cloud providers](https://cloud.ibm.com/docs/iam?topic=iam-iam-compare&format=markdown)
- [Centralized access management across your organization](https://cloud.ibm.com/docs/iam?topic=iam-cloudaccess&format=markdown)
- [Layered security with context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-context-restrictions-whatis&format=markdown)

## Tutorials

- [Assigning access to resources by using access groups](https://cloud.ibm.com/docs/iam?topic=iam-access-getstarted&format=markdown)
- [Managing access for apps in compute resources](https://cloud.ibm.com/docs/iam?topic=iam-trustedprofile-compute-tutorial&format=markdown)
- [Managing access for federated users by using trusted profiles](https://cloud.ibm.com/docs/iam?topic=iam-trustedprofile-fedusers-tutorial&format=markdown)
- [Managing access for SAP workloads in Power Virtual Server](https://cloud.ibm.com/docs/iam?topic=iam-trustedprofile-powervs-tutorial&format=markdown)
- [Leveraging context-based restrictions to secure your resources](https://cloud.ibm.com/docs/iam?topic=iam-context-restrictions-tutorial&format=markdown)

## How to

- Authentication and MFA
   - [IBM Cloud multifactor authentication](https://cloud.ibm.com/docs/iam?topic=iam-types&format=markdown)
   - [Enabling MFA in your account](https://cloud.ibm.com/docs/iam?topic=iam-enablemfa&format=markdown)
   - [Identifying a user's MFA status](https://cloud.ibm.com/docs/iam?topic=iam-id-user-mfa&format=markdown)
   - [Managing verification methods and MFA factors](https://cloud.ibm.com/docs/iam?topic=iam-verification-authentication&format=markdown)
   - [Migrating to IBM Cloud MFA](https://cloud.ibm.com/docs/iam?topic=iam-migrate-mfa&format=markdown)
   - [Deprecated legacy account-based MFA](https://cloud.ibm.com/docs/iam?topic=iam-legacy-mfa&format=markdown)
- Federation
   - [Integrating your identity provider with IBM Cloud](https://cloud.ibm.com/docs/iam?topic=iam-federation-option-for-you&format=markdown)
   - [Logging in with a federated ID](https://cloud.ibm.com/docs/iam?topic=iam-federated_id&format=markdown)
   - [Enabling authentication from an external identity provider](https://cloud.ibm.com/docs/iam?topic=iam-ibm-idp-integration&format=markdown)
   - [Managing deprecated SAML federation](https://cloud.ibm.com/docs/iam?topic=iam-saml-federation&format=markdown)
- Managing access
   - [Streamlined access management with access groups](https://cloud.ibm.com/docs/iam?topic=iam-groups&format=markdown)
   - [Managing access to resources](https://cloud.ibm.com/docs/iam?topic=iam-assign-access-resources&format=markdown)
   - [Managing users in an account](https://cloud.ibm.com/docs/iam?topic=iam-iamuserinv&format=markdown)
   - [Creating and working with service IDs](https://cloud.ibm.com/docs/iam?topic=iam-serviceids&format=markdown)
   - [Assigning access to account management services](https://cloud.ibm.com/docs/iam?topic=iam-account-services&format=markdown)
   - [Managing public access to resources](https://cloud.ibm.com/docs/iam?topic=iam-public&format=markdown)
   - [Managing migrated SoftLayer account permissions](https://cloud.ibm.com/docs/iam?topic=iam-migrated_permissions&format=markdown)
   - [Assigning access by using wildcard policies](https://cloud.ibm.com/docs/iam?topic=iam-wildcard&format=markdown)
   - [Managing classic infrastructure access](https://cloud.ibm.com/docs/iam?topic=iam-mngclassicinfra&format=markdown)
   - [Auditing access policies](https://cloud.ibm.com/docs/iam?topic=iam-iam-audit-policies&format=markdown)
   - [Auditing user access policies](https://cloud.ibm.com/docs/iam?topic=iam-audit-user-access&format=markdown)
   - [Limiting access with time and resource attribute-based conditions](https://cloud.ibm.com/docs/iam?topic=iam-iam-time-based&format=markdown)
   - [Granting access between services](https://cloud.ibm.com/docs/iam?topic=iam-serviceauth&format=markdown)
   - [Creating custom roles](https://cloud.ibm.com/docs/iam?topic=iam-custom-roles&format=markdown)
   - [Creating dynamic rules for access groups](https://cloud.ibm.com/docs/iam?topic=iam-rules&format=markdown)
   - [Identifying inactive identities](https://cloud.ibm.com/docs/iam?topic=iam-id-inactive-identities&format=markdown)
   - [Managing external identity interactions](https://cloud.ibm.com/docs/iam?topic=iam-cross-acct&format=markdown)
   - [Leaving an account](https://cloud.ibm.com/docs/iam?topic=iam-account-membership&format=markdown)
   - [Auditing access to resources](https://cloud.ibm.com/docs/iam?topic=iam-access-report&format=markdown)
- Trusted profiles
   - [Trusted profiles overview](https://cloud.ibm.com/docs/iam?topic=iam-trusted-profiles-overview&format=markdown)
   - [Trusted profiles for federated users and workloads](https://cloud.ibm.com/docs/iam?topic=iam-create-trusted-profile&format=markdown)
   - [Managing trusted profiles](https://cloud.ibm.com/docs/iam?topic=iam-trusted-profile-update&format=markdown)
   - [Generating an IAM token for a compute resource](https://cloud.ibm.com/docs/iam?topic=iam-trusted-profile-iam-token&format=markdown)
   - [Monitoring login sessions for trusted profiles](https://cloud.ibm.com/docs/iam?topic=iam-trusted-profile-monitor&format=markdown)
   - [Authenticating Power Virtual Server instances with trusted profiles](https://cloud.ibm.com/docs/iam?topic=iam-powervs-instance-identity&format=markdown)
- Context-based restrictions
   - [Creating context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-context-restrictions-create&format=markdown)
   - [Managing context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-context-restrictions-update&format=markdown)
   - [Protecting catalogs with context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-cbr&format=markdown)
   - [Protecting IAM services with context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-iam-services-cbr&format=markdown)
   - [Monitoring context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-cbr-monitor&format=markdown)
- Settings
   - [Controlling user visibility](https://cloud.ibm.com/docs/iam?topic=iam-iam-user-setting&format=markdown)
   - [Updating a user's status](https://cloud.ibm.com/docs/iam?topic=iam-status&format=markdown)
   - [Allowing specific IP addresses](https://cloud.ibm.com/docs/iam?topic=iam-ips&format=markdown)
   - [Restricting users from creating API keys](https://cloud.ibm.com/docs/iam?topic=iam-allow-api-create&format=markdown)
   - [Restricting domains for account invitations](https://cloud.ibm.com/docs/iam?topic=iam-restrict-acct-invite&format=markdown)
   - [Restricting users from creating service IDs](https://cloud.ibm.com/docs/iam?topic=iam-restrict-service-id-create&format=markdown)
   - [Updating the classic infrastructure VPN password](https://cloud.ibm.com/docs/iam?topic=iam-vpnpassword&format=markdown)
   - [Setting limits for login sessions](https://cloud.ibm.com/docs/iam?topic=iam-iam-work-sessions&format=markdown)
   - [Setting limits for IAM tokens](https://cloud.ibm.com/docs/iam?topic=iam-token-limit&format=markdown)
   - [Monitoring your login sessions](https://cloud.ibm.com/docs/iam?topic=iam-monitor-your-session&format=markdown)
   - [Increasing account limits](https://cloud.ibm.com/docs/iam?topic=iam-account-limits&format=markdown)
- API keys
   - [Understanding API keys](https://cloud.ibm.com/docs/iam?topic=iam-manapikey&format=markdown)
   - [Managing user API keys](https://cloud.ibm.com/docs/iam?topic=iam-userapikey&format=markdown)
   - [Managing service ID API keys](https://cloud.ibm.com/docs/iam?topic=iam-serviceidapikeys&format=markdown)
   - [Managing classic infrastructure API keys](https://cloud.ibm.com/docs/iam?topic=iam-classic_keys&format=markdown)
   - [Generating an IBM Cloud IAM token by using an API key](https://cloud.ibm.com/docs/iam?topic=iam-iamtoken_from_apikey&format=markdown)
   - [Invoking IBM Cloud service APIs](https://cloud.ibm.com/docs/iam?topic=iam-iamapikeysforservices&format=markdown)
- Observability
   - [Activity tracking events for IAM](https://cloud.ibm.com/docs/iam?topic=iam-at_events_iam&format=markdown)
   - [Activity tracking events for context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-at_events_cbr&format=markdown)

## Reference

- API reference
   - [IAM Access Groups](https://{DomainName}/apidocs/iam-access-groups)
   - [IAM Identity Services](https://{DomainName}/apidocs/iam-identity-token-api)
   - [IAM Policy Management](https://{DomainName}/apidocs/iam-policy-management)
   - [Context-based restrictions](https://{DomainName}/apidocs/context-based-restrictions)
- [IAM Policy Management API change log](https://cloud.ibm.com/docs/iam?topic=iam-api-change-log&format=markdown)
- Command reference
   - [Managing IAM access, API keys, trusted profiles, service IDs, and access groups (ibmcloud iam)](https://cloud.ibm.com/docs/iam?topic=iam-ibmcloud_commands_iam&format=markdown)
   - [Context-based restrictions CLI plug-in](https://cloud.ibm.com/docs/iam?topic=iam-cbr-plugin&format=markdown)
   - [Context-based restrictions CLI change log](https://cloud.ibm.com/docs/iam?topic=iam-cli-change-log&format=markdown)
- [IAM roles and actions](https://cloud.ibm.com/docs/iam?topic=iam-iam-service-roles-actions&format=markdown)
- [IBM Cloud login sequences](https://cloud.ibm.com/docs/iam?topic=iam-login-sequence&format=markdown)
- [IAM condition properties](https://cloud.ibm.com/docs/iam?topic=iam-iam-condition-properties&format=markdown)

## Help

- FAQs
   - [FAQ about IAM](https://cloud.ibm.com/docs/iam?topic=iam-iamfaq&format=markdown)
   - [FAQ about Context-based restrictions](https://cloud.ibm.com/docs/iam?topic=iam-cbrfaq&format=markdown)
- Troubleshooting
   - [Why can't a user in my account access resources from the Resource list page?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-serviceaccess&format=markdown)
   - [How do I know what access I am assigned? ](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-myaccess&format=markdown)
   - [How can I get access to invite users to the account?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-invite&format=markdown)
   - [How can I view classic infrastructure permissions for other users? ](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-classicinfra&format=markdown)
   - [How can I manage migrated billing and support case permissions in IBM Cloud?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-migrated-permissions&format=markdown)
   - [Why is a policy limit blocking me from assigning access?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-policy-limit&format=markdown)
   - [Why can't I manage a service ID that I created and previously had access to?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-serviceid-access&format=markdown)
   - [Why can't I create access management tags?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-create-accesstag&format=markdown)
   - [Why can't I attach or detach access management tags on a resource?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-attach-detach-accesstag&format=markdown)
   - [Why can't I delete access management tags?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-delete-accesstag&format=markdown)
   - [Why can't a user in my account access all instances of a service? ](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-instances&format=markdown)
   - [Why can't I log in with my MFA factors?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-MFA&format=markdown)
   - [Why can't I log in to an account I was recently added to? ](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-join-account&format=markdown)
   - [Why is my rule for all endpoint types from VPC not working as expected?](https://cloud.ibm.com/docs/iam?topic=iam-troubleshoot-cbr-vpc-public-endpoint&format=markdown)
   - [Why did the creation of an alternative account owner trusted profile fail?](https://cloud.ibm.com/docs/iam?topic=iam-ts_alt-owner&format=markdown)
- [Getting help and support](https://cloud.ibm.com/docs/iam?topic=iam-help-and-support&format=markdown)
