AWS Identity and Access Management (IAM) controls who can sign in to your AWS account (authentication) and what they are allowed to do (authorization). IAM is a global service, not tied to a Region, and it is available at no additional charge. It is the heart of the customer's security responsibility, because nearly every security failure in AWS comes down to someone having access they should not have. IAM has four building blocks. An IAM user is an identity for one person or application, with long-term credentials: a password for the console and optionally access keys for the command line interface (CLI) and software development kits (SDKs). An IAM group is a collection of users; you attach permissions to the group, and every member inherits them. Groups cannot contain other groups, and a group is not an identity that can sign in. An IAM role is an identity with permissions but no long-term credentials. Instead, a trusted entity assumes the role and receives temporary credentials from AWS Security Token Service (AWS STS). Policies define the permissions themselves.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.