Removing account roles from a group
When you unassign a role from a group, the role is also unassigned from all user and machine user accounts in the group.
Steps
Management Console UI
- Sign in to the CDP console.
- From the CDP home page, click Management Console.
- In the User Management section of the side navigation panel,
click Groups.
The Groups page displays the list of all CDP groups.
- Click the name of the group from which you want to remove the account role.
The details page displays information about the group.
- Click the Roles tab.
- From the context menu to the right of a role, click Unassign role.
- Click OK to confirm that you want to remove the role permissions from the group.
CLI
To remove a role from a
group:
cdp iam unassign-group-role \
--group-name <value> \
--role <value>
The
role parameter requires the CRN of the CDP role.To get a list of the roles assigned to a group:
cdp iam list-group-assigned-roles \
--group-name <value>