Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| assign (to a group) | add a user to a group |
| grant permissions | allow someone to do something |
| apply a principle | use a rule as a guideline |
| belong to (a group) | be a member of |
| regroup | put together into one group |
| create a policy | define a set of permissions |
| allow / deny | permit or block an action |
Technical Vocabulary
| Term | Definition |
|---|---|
| IAM | Identity and Access Management — AWS service for controlling who can do what in your AWS account |
| Root account | The main account created when you sign up for AWS; has full access; should not be used daily |
| IAM User | An identity representing one person (or application) in your AWS account |
| IAM Group | A collection of users sharing the same permissions |
| IAM Policy | A JSON document that defines what actions are allowed or denied on what AWS resources |
| JSON | JavaScript Object Notation — a text format used for IAM policies |
| Permissions | What actions a user or group is allowed to perform |
| Least privilege principle | Give users only the minimum permissions they need to do their job |
| Global service | IAM is not tied to a specific region — users and policies apply account-wide |
Key Concepts
IAM: Core Components
- Users → represent real people (or applications)
- Groups → collections of users (e.g., “developers”, “operations”)
- Policies → JSON documents attached to users/groups defining what they can do
Important Rules
- Groups can only contain users, NOT other groups
- A user can belong to multiple groups
- A user does not have to belong to any group (though not recommended)
IAM Policies (JSON)
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["ec2:Describe*", "elasticloadbalancing:Describe*", "cloudwatch:*"],
"Resource": "*"
}
]
}
This policy allows users to describe EC2, ELB, and use CloudWatch.
Root Account Rules
- Created by default when you sign up
- Has full access to everything
- Should only be used to set up the account
- Never share the root account; create IAM users instead
Least Privilege Principle
- Do NOT give more permissions than needed
- If a user only needs 3 services → create a policy for those 3 services only
- Reduces security risk if credentials are compromised
Exam Tips
- IAM is a global service (not region-specific)
- Groups contain users only — no nested groups
- Policies are JSON documents
- Always follow least privilege — never over-permission