# Limitation

**When delegating IAM** permissions on **vStorage** , there are some limitations:

1. **Object Lock Mode Governance not supported: this mode is temporarily not supported on vStorage systems, so you can use Compliance** or **Legal Hold** modes instead to ensure data protection.
2. **Restrict permissions for IAM User:** Some features cannot customize permissions for IAM User and will default to **full permissions like Root User** , including:
   * **Bucket Versioning:** IAM User can freely enable/disable versioning without any permissions.
   * **CORS Bucket:** IAM User can set up or edit, delete CORS configuration without any restrictions.
   * **Object Lock:** IAM User can enable/disable locked object mode or change **retention day** without control.

These limitations may impact your ability to tightly control permissions when working with these features. We recommend that you consider this when granting IAM User permissions in use cases involving sensitive data.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.vngcloud.vn/vng-cloud-document/vstorage/object-storage/object-storage-han02/access-management/limitation.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
