개별 Looker(Google Cloud 핵심 서비스) 사용자를 추가하려면 ID 공급업체 내에 사용자를 추가합니다. Looker 계정은 처음 로그인할 때 생성됩니다. 사용자 페이지에서는 개별 사용자를 추가할 수 없습니다. 하지만 사용자 페이지에서 API 전용 서비스 계정을 추가할 수 있습니다.
API 전용 서비스 계정 만들기
Looker(Google Cloud 핵심 서비스) 인스턴스 내 사용자 페이지에서 API 전용 계정('서비스 계정'이라고도 함)을 만들 수 있습니다. 이러한 계정에 관리자 Looker 역할과 Looker API 사용자 인증 정보를 부여할 수 있습니다. 하지만 이러한 계정은 UI를 통해 Looker(Google Cloud 핵심 서비스)에 로그인할 수 없습니다. 서비스 계정을 추가하려면 다음 단계를 수행합니다.
인증에 사용된 ID 공급업체를 업데이트하여 Looker(Google Cloud 핵심 서비스) 인스턴스에 대한 액세스 권한을 삭제합니다. 사용자가 더 이상 인스턴스에 로그인할 수 없지만 사용자 계정은 사용자 페이지에 계속 활성화된 상태로 표시됩니다. 사용자 페이지에서 사용자 계정을 삭제하려면 Looker(Google Cloud 핵심 서비스) 인스턴스 내에서 사용자를 삭제합니다.
Looker(Google Cloud 핵심 서비스) 사용자를 위한 인증 방법 선택
인스턴스 생성 시 OAuth 클라이언트를 설정해야 합니다. OAuth 인증은 Looker(Google Cloud 핵심 서비스)의 백업 인증 방법입니다. 하지만 여러 가지 기본 인증 방법 중에서 선택할 수 있습니다. Looker(Google Cloud 핵심 서비스) 인증 방법 문서 페이지에는 사용 가능한 인증 방법이 나와 있습니다.
Looker(Google Cloud 핵심 서비스) 인스턴스 내에서 기본 Looker 역할 설정
사용자를 추가하기 전에 Looker(Google Cloud 핵심 서비스) 인스턴스에 처음 로그인할 때 Looker 인스턴스 사용자 IAM 역할이 있는 사용자 계정에 부여될 기본 Looker 역할을 설정할 수 있습니다. 기본 역할을 설정하려면 ID 공급업체 문서에 제공된 단계인 OAuth, SAML 또는 OpenID Connect를 수행합니다.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2024-12-22(UTC)"],[],[],null,["# Manage users within Looker (Google Cloud core)\n\nWithin a Looker (Google Cloud core) instance, several settings are available for managing users.\n\nRequired permission\n-------------------\n\nIn order to manage users within a Looker (Google Cloud core) instance, you must have the [Admin role](/looker/docs/admin-panel-users-roles#default_permission_sets) within Looker.\n\nThe Users page\n--------------\n\nThe [**Admin \\\u003e Users** page](/looker/docs/admin-panel-users-users) within Looker displays active users within Looker (Google Cloud core) and lets you make certain edits to their accounts within Looker, such as editing the following account settings:\n\n- [locale](/looker/docs/admin-panel-users-users#locale)\n- [number format](/looker/docs/admin-panel-users-users#number_format)\n- [timezone](/looker/docs/admin-panel-users-users#timezone)\n- [Groups](/looker/docs/admin-panel-users-users#groups)\n- [Looker roles](/looker/docs/admin-panel-users-users#roles)\n\nUsers' names and email addresses must be edited within the identity provider that is used for authentication.\n\nUnlike within Looker (original) instances, the following is not available in the Looker (Google Cloud core) **Users** page:\n\n- [add users](/looker/docs/admin-panel-users-users#adding_users) (with the exception of [service accounts](#creating_an_api_only_service_account))\n- [send setup link / send reset link](/looker/docs/admin-panel-users-users#send_setup_link_send_reset_link)\n- [set up two-factor authentication](/looker/docs/admin-panel-users-users#two-factor_secret)\n- [sudo](/looker/docs/admin-panel-users-users#impersonating_sudoing_users) as a user\n\nAdding users to a Looker (Google Cloud core) instance\n-----------------------------------------------------\n\nTo add individual Looker (Google Cloud core) users, add users within your [identity provider](/looker/docs/looker-core-user-authentication). Their Looker accounts will be created upon first login. Individual users cannot be added on the **Users** page; however, API-only service accounts can be added on the **Users** page.\n| **Note:** Looker does not notify users that they have been added to the Looker (Google Cloud core) instance. You must notify users they have been added and provide login information, such as URL.\n\n### Creating an API-only service account\n\n| **Note:** Service accounts are the only accounts that can be created within a Looker (Google Cloud core) instance.\n\nYou can create [API-only accounts (often called \"service accounts\")](/looker/docs/api-auth#managing_api_credentials) from the **Users** page within a Looker (Google Cloud core) instance. These accounts can be granted Admin Looker roles and can be granted Looker API credentials. However, these accounts cannot log in to Looker (Google Cloud core) through the UI. To add a service account, follow these steps:\n\n1. Click the **Add Service Account** button.\n2. Enter an email address for the service account.\n3. Select the [Groups](/looker/docs/admin-panel-users-groups) and [Roles](/looker/docs/admin-panel-users-roles) to assign to the service account.\n4. Click the **Save** button.\n\n| **Note:** Service accounts within Looker (Google Cloud core) are not the same as [Google service accounts](/iam/docs/service-account-overview) and are not governed by IAM.\n\nRemoving access to Looker (Google Cloud core)\n---------------------------------------------\n\n| **Important:** We recommend that you remove access to a Looker (Google Cloud core) instance by using the identity provider that was used for authentication rather than by disabling or deleting the user from the **Users** page.\n|\n| \u003cbr /\u003e\n|\n| Deleting users from a Looker (Google Cloud core) instance that is [associated with a Looker Studio Pro subscription](/looker/docs/looker-core-lsp) reduces the number of complimentary Looker Studio Pro licenses that are allocated to your instance. If the number of complimentary Pro licenses that are allocated to your instance becomes less than the number that is in use, the difference will be converted immediately to paid licenses, subject to Looker Studio Pro [pricing](/looker-studio#pricing).\n\nRemove access to a Looker (Google Cloud core) instance by updating the identity provider that was used for authentication. Although the user can no longer log in to the instance, the user account will still appear active on the **Users** page. To remove the user account from the **Users** page, [delete](/looker/docs/admin-panel-users-users#deleting_users) the user within the Looker (Google Cloud core) instance.\n\nSelecting an authentication method for Looker (Google Cloud core) users\n-----------------------------------------------------------------------\n\nAn OAuth client must be set up as part of instance creation, and OAuth authentication is the backup authentication method for Looker (Google Cloud core). However, you can choose between several different primary authentication methods. The [Authentication methods for Looker (Google Cloud core)](/looker/docs/looker-core-user-authentication) documentation page lists the available authentication methods.\n\nSetting a default Looker role within the Looker (Google Cloud core) instance\n----------------------------------------------------------------------------\n\nBefore you add any users, you can set the default [Looker role](/looker/docs/admin-panel-users-roles) that will be granted to user accounts with the Looker Instance User IAM role upon their first login to a Looker (Google Cloud core) instance. To set a default role, follow the steps provided in the documentation for your identity provider: [OAuth](/looker/docs/looker-core-oauth-authentication#setting_a_default_looker_role_within_the_instance), [SAML](/looker/docs/admin-panel-authentication-saml#default_groups_and_roles), or [OpenID Connect](/looker/docs/admin-panel-authentication-openid-connect#default_groups_and_roles).\n\nWhat's next\n-----------\n\n- [Connect Looker (Google Cloud core) to your database](/looker/docs/looker-core-dialects)\n- [Configure a Looker (Google Cloud core) instance](/looker/docs/looker-core-instance-setup)\n- [Looker (Google Cloud core) admin settings](/looker/docs/looker-core-admin-looker)\n- [Administer a Looker (Google Cloud core) instance from the Google Cloud console](/looker/docs/looker-core-admin-console)"]]