Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
This guide is designed to help you navigate the Identity and Access Management (IAM) Portal, a critical component of HI GIO Cloud that enables you to manage user identities, permissions, and access controls effectively.
The IAM Portal provides a user-friendly interface for administrators and users, allowing you to create and manage user accounts, assign roles, and enforce security policies to protect your cloud resources. Whether setting up new users, configuring access rights, or monitoring activity logs, this manual offers step-by-step instructions and best practices to ensure a secure and efficient experience.
Explore the features of the HI GIO IAM Portal and empower your organization with robust identity management and access control capabilities!
Step 1: Log in to HI GIO IAM portal with domain https://iam.higiocloud.vn
Enter Organization Name NEXT
Enter user name /password SIGN IN
Login Success
Step 2: Create a new user
Select tab User ADD NEW
Fill information: please select the properties role for Portal Role. If you want to use MFA, you need to enable MFA TOTP.
Step 3: Log in with MFA TOTP.
You can enable/disable the function MFA TOTP on the IAM portal. We recommend using the MFA function for more security for your HI GIO account.
After enabling MFA TOTP, you need to Verify.
Step 4: Go to vCD portal.
HI GIO Cloud includes 2 portals: the IAM portal & vCD portal.
IAM portal: user management, billing
vCD portal: resource management, VMs…
vCDs role = IaaS Admin
Click NEXT. Verify user information and SAVE
Successfully created a new user.
Log out your account on the IAM portal. Please install one of the following applications on your mobile:
Microsoft Authenticator
Google Authenticator
FreeOTP
Log in again after entering a user name/password SIGN IN. Please Open the application and scan the barcode display on the screen.
Enter the one-time code provided by the application (Device name - optional) and click Submit to finish the setup.
Successfully activate and login with MFA TOTP
On the top right corner of HI GIO IAM portal, click your name.
Click “Open VCD Portal hcmc01” (or another site)
Click “SIGN IN WITH SAML” (No need enter user name & password)
Successfully Linked to vCD Portal.





The user will receive an email to activate account IAM (Please see file )
This short manual guide is intended to assist HI GIO users in navigating our management tools and features. Whether you are looking to optimize project workflows, monitor performance metrics, or manage user access and permissions, our solutions are tailored to meet the diverse needs of your organization.
Welcome to the HI GIO Portal, your centralized hub for accessing and managing all HI GIO Cloud services. This portal lets you easily monitor your resources, manage your account settings, and access essential support services. Whether deploying applications, analyzing performance metrics, or configuring security settings, the HI GIO Portal empowers you to take full control of your cloud environment. Let’s get started and unlock the full capabilities of your HI GIO experience!
HIGIO supports tenant users setting the Passkey factor to log in IAM portal.
Once Passkey is set, it will be the default factor when logging in.
Step 1: Log in to the HI GIO IAM portal with domain
• Enter Organization Name then click NEXT
• Enter user name /password SIGN IN
• Login success
Password Lifetime is the duration for which a password is valid. This duration will be extended whenever the password is reset.
This function allows users (Provider/Tenant) to set the lifetime of password of tenant user and all members in a tenant will have the same password lifetime.
The lifetime can be Unlimited and Limited:
o Unlimited: the password will not expire.













• Go to the User Profile -> Passkeys -> ADD NEW
• It will open a new Passkey Registration page, click REGISTER, can verify with your PIN, FaceID or Fingerprint, then click OK.
• Successfully create Passkey
Step 3. Log in with passkey.
Go to the IAM portal https://iam.higiocloud.vn , input Organization Name and login.
After entering your Username/Password, you will be asked for the Passkey. Choose your verification method and then click OK.
• Successfully logged in.
NOTE: After registering, Passkey is required by default, but you can also use the TOTP option.
• Choose VERIFY WITH TOTP
Step 4. Delete Passkey.
Log in to the IAM portal, go to the User Profile tab and choose DELETE under the Passkeys tab.
Passkey 2 MFA simplifies secure login to the IAM portal. Users authenticate using biometrics or device PIN, with credentials stored securely on their device. This enhances both security and convenience.



Whenever the password is updated, the password lifetime will start over again.
Emails will be sent to tenant users if their password is:
It will expire in the next 30 days ⇒ to remind users to change their password.
It will expire in the next 7 days ⇒ to remind users to change their password.
It will expire in the next day ⇒ to remind users to change their password.
It expired last day ⇒ To inform users that they cannot log in to the system anymore, they need to contact the administrator to reset the password.
Besides, there is an email to send to the administrator/owner of the tenant to inform the list of their members that have passwords to expire the next day.
Step 1: Login to the Tenant site by the role that has permission to change password lifetime.
Step 2: Access the Tenant setting page: General > Setting tab.
Step 3: Click on the Edit button.
Step 4: Choose Limited or Unlimited from the select box.
Step 5: If you choose Limited, the user must input the duration by days.
Step 6: Click the button to Save.
Step 1: Email to remind users to change their password.
Step 2: Email to inform users that their password is not valid anymore >> please contact the Administrator or HI GIO support to reset the password.
Step 3: Email to inform administrators/owners of the list of members.
If the password lifetime is updated, the administrator/owner of tenant must reset the password for all members to make sure the system running correctly.
This function allows users to create rules for receiving notifications via Telegram channels when the statuses of VMs exceed or fall below specific thresholds.
Step 1: Login HI GIO cloud > Monitor
Step 2: Select Manage, and Select NEW below Alert Contact Destination section
New Alert Contact Destination will open
Select Integration in Telegram
Fill up contact information to this window> SAVE
Data of BOT API Token will be hidden on the Edit form
Fields explanation:
Name: The name of the contact destination.
Integration: The channel where users can receive alerts. In this version, there are 3 channels available: Email and telegram.
BOT API Token: Token to access the BOT API
Chat ID: Group Chat ID of Telegram
Optional Webhook Settings:
+ Disable Web Page Preview: If this option is checked, a Web Page Preview will be hidden on the notification content.
+ Disable resolve message: A "resolved" notification will not be sent if this option is checked.
After completed, the Alert Contact Destination will show as below:
Step 1: Login HI GIO cloud > Monitor
Step 2: Select Manage, and Select NEW below the Alert Rules section.
A New Alert Rule window will open.
Fill up the information in this window and select Alert Contact Destination using the Telegram notification channel >
Whenever the threshold defined in the alert rule is reached, we will receive a Telegram notification indicating the Firing Instances or Resolved Instances.
Sample Telegram – Firing Instance
Sample Telegram – Resolved Instance
You will receive an activation email after you request your HI GIO account. You need to activate it in the first use.
Step 1: Check activate email, subject: no-reply-iam from no-reply-iam@higiocloud.vn
Step 2: Follow the link in the email. Click “Link to account update.”
Step 3: Click “Click here to proceed.”
Step 4: Click “Submit” to complete.
Step 5: Click “Back to Application” to log on HI GIO.
Step 6: Enter user name/password to log on to HI GIO Cloud
HI GIO’s URL:
Organization name: (The HI GIO team provided it via email, or you can get it through the activate email).
Password: that you changed in the activate steps.
This function is designed to enable users to create rules for receiving notifications if the statuses of VMs exceed or fall below specific thresholds. The resources that can be monitored and notified are:
- CPU Usage.
- Memory Usage.
- Free Disk Space.
The recipients will receive notifications when the alert is triggered.













After it is completed, the alert rule will show as below:








You need to change your password in the first login.
From the second login, you can use this information.






If you get the notification below from an active email.
It’s a safe link. This notice is due to AWS SES.
-
Select Manage, and Select NEW below the Alert Contact Destination section.
A new Alert Contact Destination will open. Fill up contact information to this window> SAVE
** Please add no-reply-iam@higiocloud.vn to the email whitelist.
An alert rule is a configuration that defines conditions under which an alert should be triggered.
Log in to HI GIO cloud > Monitor
Select Manage, and Select NEW below the Alert Rules section.
New Alert Rule window will open. Fill up the information in this window> SAVE
After it is completed, the alert rule will show as below:
We also can activate\deactivate the rules directly from this list.
Every threshold reaches the defined in the alert rule. we will get the email notification - Firing Instance\Resolved Instances.
Name: The name of the contact destination.
Integration: The channel where users can receive alerts. In this version, there is only 1 channel available: Email.
Email Address:
A catalog is a container for vApp templates\ VM templates, and media files in an organization.
HI GIO provides a public catalog that contains standard virtual machine (VM) sizes and operating systems.
The public catalog is a good place to start when deploying VMs into the HI GIO. However, you may want to create your catalogs containing specific application images, which you can then use to deploy VMs quickly.
Step 1: In the menu bar, select Libraries.
Step 2: In the left navigation panel, under Content Libraries, select Catalogs >> NEW
Step 3: In the Create Catalog dialog box, enter a Name for the catalog and give it a Description (optional).
Step 4: To specify a particular storage policy for the catalog, select the Pre-provision on specific storage policy option, then select the Storage Policy
Step 5: When you're done, click OK.
Step 6: To make the catalog visible to others within your organization, click the three vertical dots and select Share.
Step 7: In the Share Catalog dialog box, from the Share with, select:
All Users and Groups are to share the catalog with everyone in the organization.
Specific Users and Groups to share the catalog with individual or group users. With permission: Read Only, Read/Write or Full Control.
8. Click Save to complete.
You can upload new media files or new versions of existing media files to a catalog. Users accessing the catalog can open the media files with their virtual machines.
Prerequisites: This operation requires the rights included in the predefined Catalog Author role or an equivalent set of rights.
Step 1: In the top navigation bar, click Libraries, and in the left panel, select Media & Other >>Add.
Step 2: In the Upload Media dialog box:
Select the Catalog to which you want to upload the media.
Enter a
HI GIO supports the Open Virtualization Format (OVF) and Open Virtualization Appliance (OVA) specifications. If you upload an OVF file that includes OVF properties for customizing its virtual machines, those properties are preserved in the vApp template.
In the top navigation bar, click Libraries and in the left panel, select vApp Templates >> New
2. Enter a URL address of the OVF file or click the Upload icon to browse to a location accessible from your computer and select the OVF/OVA template file.
** The location might be your local hard drive, a network share, or a CD/DVD drive. The supported file extensions include .ova, .ovf, .vmdk, .mf, .cert, and .strings. If you select to upload an OVF file, which references more files than you are trying to upload. For example, a VMDK file, you must browse and select all files.
This function aims to provide tenant users/service providers a visual look at the status of each VM based on its metrics:
o CPU Usage.
o Memory Usage.
o Disk used Space.
o Disk Average number of bytes read.
o Disk Average number of bytes written.
o Network utilization on interfaces.
In this guide, we will help you:
How to enable Monitor Zones
How to view monitor items on your organization.
Step 1: Enable Monitor Zones
This page lists out all managed regions of your account and lets you enable monitoring for them.
Log on to the IAM portal. Select Monitor > Manage
Select Zone > Change to Active


Click the Upload icon and browse to the image file you want to upload.
Step 3: Click OK.
Depending on the file size, the upload might take some time to complete. You can monitor the status of the upload in the Recent Tasks view.
3. Verify the details of the OVF/OVA template you are about to deploy and click Next.
4. Enter a Name, Description (optionally) for the vApp template.
From the Catalog drop-down menu, select the catalog, to which you want to add the template and click Next.
5. Review the vApp template settings and click Finish







Log on IAM portal. Select Monitor > View.
In Monitor View window, you can select: IaaS Zone [3], oVDC [4] which one you want to view.
Select VM name from list [5] to open monitor items of VMs.
On this page, you can select:
[1] oVDC
[2] VM
[3] Network (if VM have multiple NIC)
[4] Disk (if VM have multiple disk)

The email address of the persons who will receive the alert email.
We can add multiple email addresses but only add 1 email at a time. After inputting a correct email address and pressing the Enter key, the email address will be added to the text area below, and then we can add another one.
Email Subject: The alert email’s subject.
Send a single email to all recipients check box:
If checked, 1 email will be sent to all recipients. All recipients will be displayed in “To“ field.
If not checked, each recipient will receive a separate email >> We don’t know who gets the notify email.
Name: The name of the rule.
Item: The resource that triggers the alert. For example, CPU.
Threshold: Specify specific values or ranges that activate the alert. For example, 90% (meaning that if CPU usage exceeds 90%, the alert will be triggered).
oVDC: Specify the oVDC.
VM: Specify the VM that triggers the alert. The select box will contain all VMs in the oVDC and /.*/ option indicates the selection of all VMs.
Pending Period:
The duration for which an alert remains pending after being triggered.
During this pending period, Grafana allows time for conditions to potentially resolve on their own before considering the alert fully triggered or resolved.
This feature helps avoid unnecessary alert notifications for transient issues.
For example, Pending Period = 3m → means that if the CPU exceeds 90%, the system will wait 3 minutes. Within 03 minutes, if the CPU falls behind 90%, no alert will be fired. The alert will only be fired if the CPU exceeds 90% after a 3-minute.
Repeat Interval:
It specifies how frequently the system checks whether the conditions for triggering the alert are still met after the initial alert firing.
If the conditions remain true during these intervals, the system continues to send notifications at the specified repeat interval until the alert condition is no longer met or resolved.
For example, Repeat Interval = 4h and the condition is CPU exceeds 90% → meaning that after an alert is first fired, the system will continue to fire the alert every 4 hours as long as the CPU still exceeds 90%.
Annotation – Summary, Description: The alert email’s content.
Alert Contact Destination: The destination where the alert will be sent. The select box contains all the created contact destinations.
Update the VM field If you rename the VM’s name on the porta
Alert Rule will not automatically update the VM’s name on the VM field.










The default value is 3m.






