StudyToCert

All certifications / Cloud Practitioner / Lessons

AWS Certified Cloud Practitioner CLF-C02 · Domain 2: Security and Compliance

IAM users, groups, roles and policies, and the principle of least privilege

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

AWS Identity and Access Management (IAM) controls who can sign in to your AWS account (authentication) and what they are allowed to do (authorization). IAM is a global service, not tied to a Region, and it is available at no additional charge. It is the heart of the customer's security responsibility, because nearly every security failure in AWS comes down to someone having access they should not have. IAM has four building blocks. An IAM user is an identity for one person or application, with long-term credentials: a password for the console and optionally access keys for the command line interface (CLI) and software development kits (SDKs). An IAM group is a collection of users; you attach permissions to the group, and every member inherits them. Groups cannot contain other groups, and a group is not an identity that can sign in. An IAM role is an identity with permissions but no long-term credentials. Instead, a trusted entity assumes the role and receives temporary credentials from AWS Security Token Service (AWS STS). Policies define the permissions themselves.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Cloud Practitioner for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Cloud Practitioner study plan