AWS SAA – Lecture 14: IAM Policies Deep Dive

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
attach (a policy)link a policy to a user, group, or role
inherit (a policy)receive permissions from the group you belong to
deny / allow accessblock or permit specific API calls
apply (a policy)put a policy into effect for an identity
consist ofbe made up of (structure description)

Technical Vocabulary

TermDefinition
IAM PolicyJSON document that defines what actions are allowed or denied on AWS resources
Inline policyA policy attached directly to a single user (not to a group)
VersionPolicy language version; almost always "2012-10-17"
StatementThe core block(s) of a policy; can be one or many
Sid (Statement ID)Optional identifier for a specific statement within a policy
EffectEither "Allow" or "Deny" — controls whether the statement permits or blocks
PrincipalThe account, user, or role the policy applies to
ActionThe list of AWS API calls to allow or deny (e.g., ec2:Describe*)
ResourceThe specific AWS resource(s) the action applies to (e.g., an S3 bucket ARN)
ConditionOptional — additional criteria that must be true for the statement to apply

Key Concepts

How Policy Inheritance Works

  • Policy attached to a group → all members of that group inherit it
  • Policy attached directly to a user → that user alone gets it (inline policy)
  • A user who belongs to multiple groups inherits policies from all groups

Example:

  • Developers group policy → Alice, Bob, Charles
  • Operations group policy → David, Edward
  • Audit team policy → Charles + David (both inherit this on top of their other group policy)

IAM Policy JSON Structure

{
  "Version": "2012-10-17",
  "Id": "S3-Account-Permissions",
  "Statement": [
    {
      "Sid": "1",
      "Effect": "Allow",
      "Principal": {
        "AWS": ["arn:aws:iam::123456789012:root"]
      },
      "Action": ["s3:GetObject", "s3:PutObject"],
      "Resource": ["arn:aws:s3:::my-bucket/*"]
    }
  ]
}

The 5 Key Fields to Know for the Exam

FieldRequired?Purpose
EffectYesAllow or Deny
PrincipalYes (for resource-based)Who the policy applies to
ActionYesWhich API calls
ResourceYesWhich AWS resource
ConditionNoWhen the policy applies

Exam Tips

  • "Version": "2012-10-17" — memorize this; it’s always the same
  • Effect, Principal, Action, and Resource are the 4 main fields — know them cold
  • Inline policies are attached to a single user (not shareable)
  • A user in multiple groups gets combined permissions from all groups