バックアップと DR サービスにアクセスするには、各ユーザーの Google アカウントを、管理コンソールへのアクセスを許可する IAM ロールを持つプリンシパルとして Google Cloud プロジェクト、フォルダ、または組織に追加する必要があります。(関連する IAM ロールを持つ)Google アカウント ユーザーが管理コンソールに初めてログインすると、管理コンソール ユーザーとして自動的に追加されます。管理コンソールには、ユーザーが実行できるアクションを決定する独自のロールがあります。IAM ロールは管理コンソールのロールにマッピングされます。詳細については、管理コンソールのロールのページをご覧ください。
次の表に、管理コンソールへのアクセスを許可するロールを示します。
IAM ロール
管理コンソールのロール
オーナー 1
管理者
編集者 1
管理者
バックアップと DR の管理者 1
管理者
バックアップと DR ユーザー 2
ベーシック
バックアップと DR の閲覧者 3
管理コンソールにアクセスできる
1 ユーザーが管理コンソールに初めてログインした後、管理者ロールを手動でユーザーに追加することをおすすめします。権限がないと、レポート マネージャーの管理者にはなりません。また、管理者ロールがあることも明確に示されます。このタスクを実行するには、ユーザーを編集するをご覧ください。この IAM ロールを持つユーザーが管理コンソール ロールを権限の低いロールに設定した場合でも、IAM ロールが原因で管理コンソール管理者ロールを保持します。
2 この IAM ロールを持つ Google アカウントには、管理コンソールで基本ロールのみが付与されます。管理コンソールのロールを手動で設定するには、システム管理権限を持つユーザー(管理者ロールを持つユーザーなど)が必要です。
3 Backup and DR 閲覧者の IAM ロールのみを持つ Google アカウントは、管理コンソールを表示できますが、制限付きのメニューへの読み取り専用アクセス権のみが付与されます。
管理者ロールには、すべてのロールの権限が実質的に付与されます。つまり、すべての権限が付与されるだけでなく、すべてのリソースを操作することもできます。管理コンソールのユーザーに [オーナー]、[編集者]、または [バックアップと DR 管理者] のロールがある場合、そのロールがロール割り当てパネルで選択されていなくても、自動的に管理者ロールが付与されます。これを変更する唯一の方法は、IAM ロールを変更することです。
[[["わかりやすい","easyToUnderstand","thumb-up"],["問題の解決に役立った","solvedMyProblem","thumb-up"],["その他","otherUp","thumb-up"]],[["わかりにくい","hardToUnderstand","thumb-down"],["情報またはサンプルコードが不正確","incorrectInformationOrSampleCode","thumb-down"],["必要な情報 / サンプルがない","missingTheInformationSamplesINeed","thumb-down"],["翻訳に関する問題","translationIssue","thumb-down"],["その他","otherDown","thumb-down"]],["最終更新日 2025-09-04 UTC。"],[[["\u003cp\u003eAccess to the Backup and DR Service management console requires a Google Account with a designated Identity and Access Management (IAM) role within a Google Cloud project, folder, or organization.\u003c/p\u003e\n"],["\u003cp\u003eIAM roles, such as Owner, Editor, Backup and DR Admin, Backup and DR User, and Backup and DR Viewer, map to specific management console roles, determining a user's level of access and the actions they can perform.\u003c/p\u003e\n"],["\u003cp\u003eUsers with Owner, Editor, or Backup and DR Admin IAM roles automatically receive the management console Administrator role, which grants them all possible rights and the ability to operate on every resource.\u003c/p\u003e\n"],["\u003cp\u003eThe management console's "Users" page allows for the addition, deletion, and management of multiple users, where you can modify user properties, sort content, adjust column widths, filter, and export the user list.\u003c/p\u003e\n"],["\u003cp\u003eManagement console roles are being phased out and replaced by Google Cloud IAM roles for Backup and DR Service, so any management console roles given will eventually be rendered obsolete.\u003c/p\u003e\n"]]],[],null,["# Manage users\n\n| **Caution:** Management console user rights and roles will be deprecated in the near future and will be replaced with Google Cloud [Identity and Access Management (IAM)](/backup-disaster-recovery/docs/access-control) roles for Backup and DR Service.\n\nTo access the Backup and DR Service, each user needs a Google Account\nadded to a Google Cloud project, folder, or organization as a principal with\nan IAM role that allows access to the management console. The first time a\nGoogle Account user (with the relevant IAM role) logs into the management\nconsole they are automatically added as a management console user. The\nmanagement console has its own roles which determines what actions that user can\ntake. Your IAM role will map to a management console role.\nSee the\n[Management console roles](/backup-disaster-recovery/docs/create-plan/manage-roles)\npage for more details.\n\nThe following table describes the roles that grant access to the management\nconsole.\n\n^1^ After the user first logs in to the management console, it is\nrecommended to manually add the administrator role to their user. Without it\nthey won't be an administrator in **Report Manager** . It also makes it\nclear that they have the administrator role. See the\n[Edit a user](/backup-disaster-recovery/docs/concepts/manage-users#edit-user)\nsection to perform this task. Note that if a user with this IAM role\nsets their management console role to a less powerful one, they will still hold\nthe management console administrator role because of their IAM role.\n\n^2^ A Google Account with this IAM role only has the **Basic** role\non the management console. They need a user with **System Manage** rights\n(such as any user who has the administrator role) to manually set their\nmanagement console role.\n\n^3^ A Google Account who only has the Backup and DR Viewer\nIAM role can view the management console with\nread-only access to limited menus.\n\nThe administrator role effectively has the rights of every role, meaning they\nnot only have all possible rights, they can also operate on every resource.\nAny management console user who has the **Owner** , **Editor** , or\n**Backup and DR Admin** role is automatically placed into the\nadministrator role, even if that role is not selected in the role assignment\npanel. The only way to change this is to change their IAM role.\n\nTo assign IAM roles to a user:\n\n1. In the Google Cloud console, go to the **IAM** page.\n\n [Go\n to IAM](https://console.cloud.google.com/projectselector/iam-admin/iam?supportedpurview=project,folder,organizationId)\n2. Click a **Select a project** drop-down menu at the top of the page.\n\n3. Select the project for which you want to view users.\n\n4. Find the principal's email address, domain, or other identifier in\n **Principals** and select **Edit principal**.\n\n5. The **Select a role** drop-down menu displays all the roles (including\n any custom roles) that you can grant to the principal on this resource.\n Search for Backup and DR and assign Backup and DR Admin or Backup and DR\n User roles.\n\nThe management console lets you add, delete, and manage multiple users.\nThe management console roles are assigned to each user such that the user\nreceives the proper authorization to execute certain functions within the\nmanagement console for managed appliances. The **Users** page under the\n**Manage** tab lists all of the users that have logged in or been manually added\nin the management console.\n\nYou can create a management console role and assign rights to the role. Based on\nthe rights assigned to a user's role, a user can also be constrained from using\nor viewing the various components of the management console. From the **Users**\npage, you can see information such as username, timezone, ID, and creation date.\nYou can modify the display of fields that appear in the **Users** list, and\nyou can also use the filter feature to locate specific users.\n\nView users in the management console\n------------------------------------\n\nUse these instructions to view users in the management console:\n\n1. Click the **Manage** tab and select **Users** from the drop-down menu. The **Users** page opens listing all appliances managed by the management console.\n2. To modify the display of the user properties, you can do the following:\n\n - **Adjust Fields**: To modify the fields that appear in the table, right-click within the table header row and click the checkboxes for the fields you want displayed (or those fields you don't want to view).\n - **Sort Content**: To sort the content listed in a table column by alphanumeric order, select a column header and then click the up or down arrow to change the order.\n - **Adjust Column Width**: To adjust the width of a table column to show more content in the table, drag the column divider in a column header to the left or right to resize the column width. Column dividers are marked by a pair of thin gray lines.\n - **Filter By** : To filter the list, enter one or more filter criteria\n as appropriate. (If you don't see the **Filter By** area,\n click **show filter** ). To clear a filter, click the **x**\n to the right of the applied filter.\n\n | **Note:** Filters that are of type text, list, and date, persist across different management console sessions for the same user.\n3. To export the user list click the **Export** icon. You can export in PDF\n format.\n\nCreate a user\n-------------\n\n| **Note:** The **Create User** option cannot create a Google Account, it can only pre-add it to the management console. Doing so lets you predefine their management console role. Google Account users are created outside of Backup and DR Service.\n\nUse these instructions to create a new user:\n\n1. Click the **Manage** tab and select **Users** from the drop-down menu. The **Users** page opens listing all users managed by the management console.\n2. Click **Create User** to open the **Create User** page.\n3. Enter the name of the new user in the **Username** field. The **Username** field is case sensitive.\n4. Select the user's time zone from the **Timezone** drop-down list.\n5. From the **Roles** area in the **Create User** window, check the checkboxes\n for the roles that you would like to assign to this user. The **Basic**\n option is selected by default.\n\n6. Click **Save User**.\n\nEdit a user\n-----------\n\nUse these instructions to edit information about an existing user:\n\n1. Click the **Manage** tab and select **Users** from the\n drop-down menu.\n\n The **Users** page opens.\n2. Select the user from the list that you want to modify and then select\n **Edit** (bottom right-hand corner of the page).\n\n The **Edit User** page opens. You can also right-click on the user in the\n list and select **Edit** from the menu.\n3. Make modifications to the user as described in **Creating a New User**.\n\n4. Click **Save User** to accept the changes.\n\nDelete a user\n-------------\n\nYou need **System Manage** rights to delete a user.\n| **Note:** The **Delete User** option does not delete the Google Account, it will only remove the user from the management console. If the user has a relevant IAM role they are able to sign in again and they are automatically added to the management console, although a user with the Backup and DR User IAM role loses any management console roles that they previously had.\n\nUse these instructions to delete a user:\n\n1. Click the **Manage** tab and select **Users** from the drop-down menu.\n\n The **Users** page opens listing all appliances managed by the management\n console.\n2. Select the user from the list and then select **Delete**\n (bottom right-hand corner of the page). You can also right-click on the user\n in the list and select **Delete** from the menu.\n\n3. Click **Confirm** in the confirmation dialog."]]