Permissions that you grant to an IAM user on the IAM console have not been applied.
Solution: Ask the administrator to modify the permissions granted to the user group to which the IAM user belongs. For details, see "Viewing or Modifying User Group Information" in the Identity and Access Management User Guide. For details about permissions, see "System-defined Permissions".
View the system-defined permissions granted to the IAM user and check whether there is a policy statement that denies the action. For details, see "Permissions Management" > "Basic Concepts" > "Policy Syntax" in the Identity and Access Management User Guide. If the system-defined permissions cannot meet your requirements, create a custom policy to allow the action. For details, see "Creating a Custom Policy" in the Identity and Access Management User Guide.
Solution: Add the user to the target user group as the administrator. For details, see "User Group Management" > "Adding IAM Users to or Removing IAM Users from a User Group" in the Identity and Access Management User Guide.
Assign permissions to the user group in specific regions. If you have assigned the user only permissions for a default region-specific project, the user does not have permissions for the subprojects. In this case, assign permissions for the required subproject. For details, see "User Group Management" > "Creating a User Group and Assigning Permissions" in the Identity and Access Management User Guide.
Remind the user to switch to the region where the user is authorized to use cloud resources. For details, see "Project Management" > "Switching Regions or Projects" in the Identity and Access Management User Guide.
Check the permissions after 15 to 30 minutes and try again.
Clear the browser cache and try again.
Modify the permissions of the user on the IAM console.
Symptom: You have granted an IAM user only required permissions but the user has more permissions.
Possible causes: