

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# Directory Service API 权限：操作、资源和条件参考
<a name="UsingWithDS_IAM_ResourcePermissions"></a>

在设置 [访问控制](iam_auth_access.md#access_control) 和编写您可附加到 IAM 身份的权限策略（基于身份的策略）时，可以使用 [Directory Service API 权限：操作、资源和条件参考](#UsingWithDS_IAM_ResourcePermissions) 表作为参考。表中的每个 API 条目都包含以下内容：
+ 每个 API 操作的名称
+ 您可授予权限进行执行的每个 API 操作的对应操作
+ 您可以在其中授予权限的 AWS 资源

 您在策略的 `Action` 字段中指定操作，并在策略的 `Resource` 字段中指定资源值。要指定操作，请在 API 操作名称之前使用 `ds:` 前缀（例如，`ds:CreateDirectory`）。某些 AWS 应用程序可能需要在其策略中使用非公共 Directory Service API 操作，例如`ds:AuthorizeApplication``ds:CheckAlias``ds:CreateIdentityPoolDirectory``ds:GetAuthorizedApplicationDetails`、`ds:UpdateAuthorizedApplication`、、、和`ds:UnauthorizeApplication`。

有些 Directory Service APIs 只能通过 AWS 管理控制台. 它们不是公开的 APIs，从某种意义上说，它们不能以编程方式调用，也不是由任何 SDK 提供的。它们接受用户凭证。这些 API 操作包括 `ds:DisableRoleAccess`、`ds:EnableRoleAccess` 和 `ds:UpdateDirectory`。

 您可以在 Directory Service 和 Directory Service Data 策略中使用 AWS 全局条件键来表达条件。有关 AWS 密钥的完整列表，请参阅 *IAM 用户指南*中的[可用全局条件密钥](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#AvailableKeys)。

## Directory Service API 和操作所需的权限
<a name="actions-related-to-objects-table"></a>


| Directory Service API 操作 | 所需权限（API 操作） | 资源 | 
| --- | --- | --- | 
| [AcceptSharedDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_AcceptSharedDirectory.html)  | ds:AcceptSharedDirectory | \* | 
| [AddIpRoutes](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_AddIpRoutes.html)  | `ds:AddIpRoutes`<br />`ec2:DescribeSecurityGroup`<br />`ec2:AuthorizeSecurityGroupIngress`<br />`ec2:AuthorizeSecurityGroupEgress` | \* | 
| [AddTagsToResource](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_AddTagsToResource.html)  | ds:AddTagsToResource`ec2:CreateTags` | \* | 
| [CancelSchemaExtension](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CancelSchemaExtension.html)  | ds:CancelSchemaExtension | \* | 
|  [ConnectDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ConnectDirectory.html)  | `ds:ConnectDirectory`<br />`ec2:DescribeSubnets`<br />`ec2:DescribeVpcs`<br />`ec2:CreateSecurityGroup`<br />`ec2:CreateNetworkInterface`<br />`ec2:DescribeNetworkInterfaces`<br />`ec2:AuthorizeSecurityGroupIngress`<br />`ec2:AuthorizeSecurityGroupEgress`<br />`ec2:CreateTags` | \* | 
|  [CreateAlias](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateAlias.html)  | `ds:CreateAlias` | \* | 
|  [CreateComputer](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateComputer.html)  | `ds:CreateComputer` | \* | 
|  [CreateConditionalForwarder](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateConditionalForwarder.html)  | `ds:CreateConditionalForwarder` | \* | 
|  [CreateDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateDirectory.html)  | `ds:CreateDirectory`<br />`ec2:DescribeSubnets`<br />`ec2:DescribeVpcs`<br />`ec2:CreateSecurityGroup`<br />`ec2:CreateNetworkInterface`<br />`ec2:DescribeNetworkInterfaces`<br />`ec2:AuthorizeSecurityGroupIngress`<br />`ec2:AuthorizeSecurityGroupEgress`<br />`ec2:CreateTags` | \* | 
| [CreateLogSubscription](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateLogSubscription.html)  | ds:CreateLogSubscription | \* | 
|  [CreateMicrosoft广告](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateMicrosoftAD.html)  | `ds:CreateMicrosoftAD`<br />`ec2:DescribeSubnets`<br />`ec2:DescribeVpcs`<br />`ec2:CreateSecurityGroup`<br />`ec2:CreateNetworkInterface`<br />`ec2:DescribeNetworkInterfaces`<br />`ec2:AuthorizeSecurityGroupIngress`<br />`ec2:AuthorizeSecurityGroupEgress`<br />`ec2:RevokeSecurityGroupEgress`<br />`ec2:CreateTags` | \* | 
|  [CreateSnapshot](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateSnapshot.html)  | `ds:CreateSnapshot` | \* | 
|  [CreateTrust](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_CreateTrust.html)  | `ds:CreateTrust` | \* | 
|  [DeleteConditionalForwarder](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DeleteConditionalForwarder.html)  | `ds:DeleteConditionalForwarder` | \* | 
|  [DeleteDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DeleteDirectory.html)  | `ds:DeleteDirectory`<br />`ec2:DescribeNetworkInterfaces`<br />`ec2:DeleteSecurityGroup`<br />`ec2:DeleteNetworkInterface`<br />`ec2:RevokeSecurityGroupIngress`<br />`ec2:RevokeSecurityGroupEgress`<br />`ec2:DeleteTags` | \* | 
| [DeleteLogSubscription](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DeleteLogSubscription.html)  | ds:DeleteLogSubscription | \* | 
|  [DeleteSnapshot](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DeleteSnapshot.html)  | `ds:DeleteSnapshot` | \* | 
|  [DeleteTrust](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DeleteTrust.html)  | `ds:DeleteTrust` | \* | 
|  [DeregisterEventTopic](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DeregisterEventTopic.html)  | `ds:DeregisterEventTopic` | \* | 
|  [DescribeConditionalForwarders](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeConditionalForwarders.html)  | `ds:DescribeConditionalForwarders` | \* | 
|  [DescribeDirectories](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeDirectories.html)  | `ds:DescribeDirectories` | \* | 
| [DescribeDomainControllers](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeDomainControllers.html)  | ds:DescribeDomainControllers | \* | 
|  [DescribeEventTopics](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeEventTopics.html)  | `ds:DescribeEventTopics` | \* | 
| [DescribeSharedDirectories](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeSharedDirectories.html)  | ds:DescribeSharedDirectories | \* | 
|  [DescribeSnapshots](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeSnapshots.html)  | `ds:DescribeSnapshots` | \* | 
|  [DescribeTrusts](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DescribeTrusts.html)  | `ds:DescribeTrusts` | \* | 
|  [DisableRadius](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DisableRadius.html)  | `ds:DisableRadius` | \* | 
|  [DisableSso](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_DisableSso.html)  | `ds:DisableSso` | \* | 
|  [EnableRadius](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_EnableRadius.html)  | `ds:EnableRadius` | \* | 
|  [EnableSso](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_EnableSso.html)  | `ds:EnableSso` | \* | 
|  [GetDirectoryLimits](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_GetDirectoryLimits.html)  | `ds:GetDirectoryLimits` | \* | 
|  [GetSnapshotLimits](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_GetSnapshotLimits.html)  | `ds:GetSnapshotLimits` | \* | 
| [ListIpRoutes](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ListIpRoutes.html) | `ds:ListIpRoutes` | \* | 
| [ListLogSubscriptions](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ListLogSubscriptions.html)  | ds:ListLogSubscriptions | \* | 
| [ListSchemaExtensions](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ListSchemaExtensions.html) | `ds:ListSchemaExtensions` | \* | 
| [ListTagsForResource](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ListTagsForResource.html) | `ds:ListTagsForResource` | \* | 
|  [RegisterEventTopic](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_RegisterEventTopic.html)  | `ds:RegisterEventTopic`<br />`sns:GetTopicAttributes` | \* | 
| [RejectSharedDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_RejectSharedDirectory.html)  | ds:RejectSharedDirectory | \* | 
| [RemoveIpRoutes](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_RemoveIpRoutes.html) | `ds:RemoveIpRoutes` | \* | 
| [RemoveTagsFromResource](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_RemoveTagsFromResource.html) | `ds:RemoveTagsFromResource`<br />`ec2:DeleteTags` | \* | 
| [ResetUserPassword](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ResetUserPassword.html)  | ds:ResetUserPassword | \* | 
|  [RestoreFromSnapshot](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_RestoreFromSnapshot.html)  | `ds:RestoreFromSnapshot` | \* | 
| [ShareDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_ShareDirectory.html)  | `ds:ShareDirectory`<br />`organizations:DescribeAccount`<br />`organizations:DescribeOrganization`<br />`organizations:ListAWSServiceAccessForOrganization` | \* | 
| [StartSchemaExtension](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_StartSchemaExtension.html) | `ds:StartSchemaExtension` | \* | 
| [UnshareDirectory](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_UnshareDirectory.html)  | ds:UnshareDirectory | \* | 
|  [UpdateConditionalForwarder](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_UpdateConditionalForwarder.html)  | `ds:UpdateConditionalForwarder` | \* | 
| [UpdateNumberOfDomainControllers](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_UpdateNumberOfDomainControllers.html)  | `ds:UpdateNumberOfDomainControllers`<br />`ec2:DescribeSubnets`<br />`ec2:DescribeVpcs`<br />`ec2:CreateNetworkInterface`<br />`ec2:DescribeNetworkInterfaces`<br />`ec2:DeleteNetworkInterface` | \* | 
|  [UpdateRadius](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_UpdateRadius.html)  | `ds:UpdateRadius` | \* | 
| [UpdateTrust](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_UpdateTrust.html)  | ds:UpdateTrust | \* | 
|  [VerifyTrust](https://docs.aws.amazon.com/directoryservice/latest/devguide/API_VerifyTrust.html)  | `ds:VerifyTrust` | \* | 

## AWS Directory Service Data API 和操作所需的权限
<a name="DSData_ResourcePermissions"></a>

**注意**  
 要指定操作，请在 API 操作名称之前使用 `ds-data:` 前缀（例如，`ds-data:AddGroupMember`）。


| Directory Service Data API 操作 | 所需权限（API 操作） | 资源 | 
| --- | --- | --- | 
|  [AddGroupMember](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_AddGroupMember.html)  | `ds-data:AddGroupMember` | \* | 
|  [CreateGroup](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_CreateGroup.html)  | `ds-data:CreateGroup` | \* | 
|  [CreateUser](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_CreateUser.html)  | `ds-data:CreateUser` | \* | 
|  [DeleteGroup](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_DeleteGroup.html)  | `ds-data:DeleteGroup` | \* | 
|  [DeleteUser](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/DeleteUser.html)  | `ds-data:DeleteUser` | \* | 
|  [DescribeGroup](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_DescribeGroup.html)  | `ds-data:DescribeGroup` | \* | 
|  [DescribeUser](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_DescribeUser.html)  | `ds-data:DescribeUser` | \* | 
|  [DisableUser](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_DisableUser.html)  | `ds-data:DisableUser` | \* | 
|  [ListGroups](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_ListGroups.html)  | `ds-data:ListGroups` | \* | 
|  [ListGroupMembers](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_ListGroupMembers.html)  | `ds-data:ListGroupMembers` | \* | 
|  [ListGroupsForMember](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_ListGroupsForMember.html)  | `ds-data:ListGroupsForMember` | \* | 
|  [ListUsers](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_ListUsers.html)  | `ds-data:ListUsers` | \* | 
|  [RemoveGroupMember](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_RemoveGroupMember.html)  | `ds-data:RemoveGroupMember` | \* | 
|  [SearchGroups](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_SearchGroups.html)  | `ds-data:DescribeGroup`<br />`ds-data:SearchGroups` | \* | 
| [SearchUsers](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_SearchUsers.html) | `ds-data:DescribeUser`<br />`ds-data:SearchUsers` | \* | 
| [UpdateGroup](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_UpdateGroup.html) | `ds-data:UpdateGroup` | \* | 
| [UpdateUser](https://docs.aws.amazon.com/directoryservicedata/latest/DirectoryServiceDataAPIReference/API_UpdateUser.html) | `ds-data:UpdateUser` | \* | 

## 相关主题
<a name="iam2_related"></a>
+ [访问控制](iam_auth_access.md#access_control)