AWS SAA – Lecture 30: IAM Summary

Published on
Written by Henry Nguyen

IAM Summary — Quick Reference

ConceptKey Point
UsersMap to real people; each has a password for the AWS console
GroupsCollections of users only (no nested groups); share policies
PoliciesJSON documents defining permissions; attached to users or groups
RolesIdentities for AWS services (EC2, Lambda, etc.) to call AWS APIs
MFAMulti-Factor Authentication for security on top of passwords
Password PolicyRules for strength, expiry, and reuse of passwords
CLICommand line tool; uses access keys; commands start with aws
SDKLanguage libraries (Python, JS, etc.) embedded in app code; uses access keys
Access KeysCredentials for CLI/SDK; treat like passwords; never share
Credentials ReportAccount-level audit: all users + credential status
Access AdvisorUser-level audit: which services were granted + last used

The IAM Mental Model

AWS Account
├── Root Account (setup only, never daily use)
└── IAM
    ├── Users (1 user = 1 person)
    │   └── belong to → Groups
    ├── Groups
    │   └── have attached → Policies (JSON)
    ├── Policies (JSON)
    │   └── define → what Actions on what Resources with what Effect
    └── Roles
        └── assumed by → AWS Services (EC2, Lambda, CloudFormation...)

Exam Cheat Sheet

  • Root account → only for setup; use IAM user for everything else
  • 1 person = 1 IAM user; never share accounts
  • Permissions = policies (JSON); attached to users OR groups
  • Services need roles, not users
  • CLI/SDK → access keys (not passwords)
  • Audit with: Credentials Report (account) + Access Advisor (user)
  • MFA = password + physical/virtual device