Home > Storage > ObjectScale and ECS > Industry Solutions and Verticals > Dell ECS and Veeam Backup & Replication > Create IAM accounts on ECS
Before creating an object-based backup repository, create an IAM-based user access key and secret, and create an S3 bucket with Object Lock enabled on the ECS system.
If you do not have an IAM group already created, create one as follows:
For this test, we create a group with all access granted. For production systems, consider the correct level of access to be granted.
For this test, we select an ECS namespace that does not have ADO enabled as the default because we want to use the Veeam immutability functionality with the buckets that we create. For more information about ECS namespaces, ADO, and immutable bucket creation on ECS, see the ECS Info Hub.
Note: You might want to restrict these policies in production.
In this example, we have created an ISM Group with policies that you might not want to grant in production.
Create an IAM user as follows:
ECS creates an access key ID and access secret key.
Once you leave this page, you cannot look up the secret key again.