AWS SAA – Lecture 11: IAM Introduction – Users, Groups, Policies

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
assign (to a group)add a user to a group
grant permissionsallow someone to do something
apply a principleuse a rule as a guideline
belong to (a group)be a member of
regroupput together into one group
create a policydefine a set of permissions
allow / denypermit or block an action

Technical Vocabulary

TermDefinition
IAMIdentity and Access Management — AWS service for controlling who can do what in your AWS account
Root accountThe main account created when you sign up for AWS; has full access; should not be used daily
IAM UserAn identity representing one person (or application) in your AWS account
IAM GroupA collection of users sharing the same permissions
IAM PolicyA JSON document that defines what actions are allowed or denied on what AWS resources
JSONJavaScript Object Notation — a text format used for IAM policies
PermissionsWhat actions a user or group is allowed to perform
Least privilege principleGive users only the minimum permissions they need to do their job
Global serviceIAM is not tied to a specific region — users and policies apply account-wide

Key Concepts

IAM: Core Components

  • Users → represent real people (or applications)
  • Groups → collections of users (e.g., “developers”, “operations”)
  • Policies → JSON documents attached to users/groups defining what they can do

Important Rules

  • Groups can only contain users, NOT other groups
  • A user can belong to multiple groups
  • A user does not have to belong to any group (though not recommended)

IAM Policies (JSON)

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["ec2:Describe*", "elasticloadbalancing:Describe*", "cloudwatch:*"],
      "Resource": "*"
    }
  ]
}

This policy allows users to describe EC2, ELB, and use CloudWatch.

Root Account Rules

  • Created by default when you sign up
  • Has full access to everything
  • Should only be used to set up the account
  • Never share the root account; create IAM users instead

Least Privilege Principle

  • Do NOT give more permissions than needed
  • If a user only needs 3 services → create a policy for those 3 services only
  • Reduces security risk if credentials are compromised

Exam Tips

  • IAM is a global service (not region-specific)
  • Groups contain users only — no nested groups
  • Policies are JSON documents
  • Always follow least privilege — never over-permission