IAM controls who can access AWS and what they are allowed to do.

Core idea

IAM stands for Identity and Access Management.

It answers two questions:

IAM is one of the most important AWS services because misconfigured permissions can expose an entire system.

Users

An IAM user usually represents a person or long-lived identity.

For human access, prefer IAM Identity Center where possible. Avoid creating many long-lived access keys for people.

Roles

An IAM role is an identity with permissions that can be assumed temporarily.

Common role use cases:

Roles are safer than storing permanent credentials in code.

Policies

A policy is a JSON document that allows or denies actions.

Policy parts include:

Example action: s3:GetObject.

Least privilege

Least privilege means giving only the permissions actually needed.

Bad:

Better:

Backend example

An EC2 server needs to read uploaded files from S3.

Use an IAM role attached to the EC2 instance with only the required S3 read permission. Do not put AWS access keys inside application code.

Quick revision