IAM Summary — Quick Reference
| Concept | Key Point |
|---|---|
| Users | Map to real people; each has a password for the AWS console |
| Groups | Collections of users only (no nested groups); share policies |
| Policies | JSON documents defining permissions; attached to users or groups |
| Roles | Identities for AWS services (EC2, Lambda, etc.) to call AWS APIs |
| MFA | Multi-Factor Authentication for security on top of passwords |
| Password Policy | Rules for strength, expiry, and reuse of passwords |
| CLI | Command line tool; uses access keys; commands start with aws |
| SDK | Language libraries (Python, JS, etc.) embedded in app code; uses access keys |
| Access Keys | Credentials for CLI/SDK; treat like passwords; never share |
| Credentials Report | Account-level audit: all users + credential status |
| Access Advisor | User-level audit: which services were granted + last used |
The IAM Mental Model
AWS Account
├── Root Account (setup only, never daily use)
└── IAM
├── Users (1 user = 1 person)
│ └── belong to → Groups
├── Groups
│ └── have attached → Policies (JSON)
├── Policies (JSON)
│ └── define → what Actions on what Resources with what Effect
└── Roles
└── assumed by → AWS Services (EC2, Lambda, CloudFormation...)
Exam Cheat Sheet
- Root account → only for setup; use IAM user for everything else
- 1 person = 1 IAM user; never share accounts
- Permissions = policies (JSON); attached to users OR groups
- Services need roles, not users
- CLI/SDK → access keys (not passwords)
- Audit with: Credentials Report (account) + Access Advisor (user)
- MFA = password + physical/virtual device