The Wayback Machine - https://web.archive.org/web/20240824142502/https://www.geeksforgeeks.org/identity-and-access-management-iam-in-amazon-web-services-aws/
Open In App

Identity and Access Management (IAM) in Amazon Web Services (AWS)

Last Updated : 18 Apr, 2023
Comments
Improve
Suggest changes
Like Article
Like
Save
Share
Report
News Follow

Pre-requisite: AWS

Identity and Access Management (IAM) manages Amazon Web Services (AWS) users and their access to AWS accounts and services. It controls the level of access a user can have over an AWS account & set users, grant permission, and allows a user to use different features of an AWS account. Identity and access management is mainly used to manage users, groups, roles, and Access policies The account we created to sign in to Amazon web services is known as the root account and it holds all the administrative rights and has access to all parts of the account. The new user created an AWS account, by default they have no access to any services in the account & it is done with the help of IAM that the root account holder can implement access policies and grant permission to the user to access certain services. 

How IAM Works?

IAM verifies that a user or service has the necessary authorization to access a particular service in the AWS cloud. We can also use IAM to grant the right level of access to specific users, groups, or services. For example, we can use IAM to enable an EC2 instance to access S3 buckets by requesting fine-grained permissions. 

IAM Work Flow

 

What Does IAM Do?

With the help of IAM, we perform the following 

IAM Identities

IAM Identities assists us in controlling which users can access which services and resources in the AWS Console and also we can assign policies to the users, groups, and roles. The IAM Identities can be created by using the Root user 

IAM Identities Classified As

  1. IAM Users
  2. IAM Groups
  3. IAM Roles

Root user 

The root user will automatically be created and granted unrestricted rights. We can create an admin user with fewer powers to control the entire Amazon account.

IAM Users

We can utilize IAM users to access the AWS Console and their administrative permissions differ from those of the Root user and if we can keep track of their login information.

Example

With the aid of IAM users, we can accomplish our goal of giving a specific person access to every service available in the Amazon dashboard with only a limited set of permissions, such as read-only access. Let’s say user-1 is a user that I want to have read-only access to the EC2 instance and no additional permissions, such as create, delete, or update. By creating an IAM user and attaching user-1 to that IAM user, we may allow the user access to the EC2 instance with the required permissions.

IAM Groups

A group is a collection of users, and a single person can be a member of several groups. With the aid of groups, we can manage permissions for many users quickly and efficiently.

Example

Consider two users named user-1 and user-2. If we want to grant user-1 specific permissions, such as the ability to delete, create, and update the auto-calling group only, and if we want to grant user-2 all the necessary permissions to maintain the auto-scaling group as well as the ability to maintain EC2, we can create groups and add this user to them. If a new user is added, we can add that user to the required group with the necessary permissions.

IAM Roles

While policies cannot be directly given to any of the services accessible through the Amazon dashboard, IAM roles are similar to IAM users in that they may be assumed by anybody who requires them. By using roles, we can provide AWS Services access rights to other AWS Services.

Example

Consider Amazon EKS. In order to maintain an autoscaling group, AWS eks needs access to EC2 instances. Since we can’t attach policies directly to the eks in this situation, we must build a role and then attach the necessary policies to that specific role and attach that particular role to EKS. 

IAM Policies 

IAM Policies can manage access for AWS by attaching them to the IAM Identities or resources IAM policies defines permissions of AWS identities and AWS resources when a user or any resource makes a request to AWS will validate these policies and confirms whether the request to be allowed or to be denied. AWS policies are stored in the form of Jason format the number of policies to be attached to particular IAM identities depends upon no.of permissions required for one IAM identity. IAM identity can have multiple policies attached to them.  

IAM Features

Shared Access to your Account: A team working on a project can easily share resources with the help of the shared access feature.

  • Free of cost: IAM feature of the Aws account is free to use & charges are added only when you access other Amazon web services using IAM users.
  • Have Centralized control over your Aws account: Any new creation of users, groups, or any form of cancellation that takes place in the Aws account is controlled by you, and you have control over what & how data can be accessed by the user.
  • Grant permission to the user: As the root account holds administrative rights, the user will be granted permission to access certain services by IAM.
  • Multifactor Authentication: Additional layer of security is implemented on your account by a third party, a six-digit number that you have to put along with your password when you log into your accounts.

Previous Article
Next Article

Similar Reads

Identity and Access Management (IAM) vs Security Information and Event Management (SIEM)
Identity and Access Management (IAM) and Security Information and Event Management (SIEM) are two critical components of an organization's security posture. Both are designed to ensure the protection of sensitive data, resources, and systems, but they do so in different ways. IAM focuses on managing who has access to resources and what they can do
8 min read
Amazon DynamoDB - Identity and Access Management(IAM)
Security in the cloud remains one of the main barriers to cloud adoption. For security operations and development teams to follow security best practices ensuring a smooth transition. AWS IAM (Identity and Access Management) is one of the most widely used security platforms for data protection. It follows an incredibly granular approach in providin
7 min read
Amazon Web Services - Denying Access using IAM policy for EC2 and EBS Instance
In this article, we will look into how to use AWS identity and access management policy conditions to create an IAM policy that denies access to create amazon elastic compute cloud instances and amazon elastic block store volumes when the required tags are not passed along with the creation request. We will also look into how you can use the IAM po
4 min read
Amazon Web Services - Limit Privileges of IAM user in RDS instance
Amazon RDS or Amazon Relational Database System is a highly scalable, secure, compact, and cost-efficient relational database in the cloud offered by AWS. In this article, we are going to look into how to limit access of AWS IAM users to an Amazon RDS(Relational Database Service) instance. Then we will explore how to give the least privileges requi
2 min read
Amazon Web Service (AWS) IAM Role VS Group
Amazon IAM Service is one of the most crucial components in the AWS security architecture. Here in this guide, i will first cover what is IAM service. Then i will discuss what is IAM Role and also guide you through the steps to create an AWS IAM Role. After this, I will discuss about IAM group and also the steps to create an IAM group. Then finally
5 min read
Difference Between AWS (Amazon Web Services) ECS And AWS Fargate
While both AWS ECS and Fargate play in the container orchestration field, their approaches diverge like two paths on a mountain trail. ECS empowers you with direct control over the underlying infrastructure, like an experienced builder crafting a custom container home. You choose and manage the bricks and mortar (EC2 instances) for a personalized c
8 min read
Machine Learing (ML) Services Offered By Amazon Web Services (AWS)
In today's rapidly evolving technologies, harnessing the power of cloud computing has become imperative for businesses striving to stay ahead. Among the many cloud computing platforms, AWS is the most used cloud computing platform. In this guide, I will make sure that you will understand what is AWS and why cloud computing services are important to
10 min read
AWS CLI For Identity And Access Management
Amazon Web Services (AWS) is a comprehensive cloud computing platform offering many services, including storage, computing, databases, and more. AWS Identity and Access Management (IAM) is a core AWS service that allows you to securely control who can access your AWS resources and what actions they can perform. IAM enables you to create users, grou
4 min read
Amazon Web Services - Copy an Amazon Redshift Cluster to Different AWS Account
In this article, we will look into how to copy an Amazon Redshift cluster from one account to a different account. Usually, users perform this operation from a production account to a quality account but you can use the steps to move a cluster from one account to another account in the same region. To do so follow the below steps: Step 1: In the ac
3 min read
Securing AWS Lambda Functions With IAM Roles And Policies
AWS Lambda is a serverless computing service that helps in executing code without any management of servers while AWS IAM is an essential security component that allows authorized individuals or services to have access of other AWS resources. These two AWS services are very important on the AWS cloud platform. Here in this guide, I have first discu
5 min read
How to create an IAM user in AWS
In this, the title IAM stands for Identity Access Management. When we working on cloud services in a company. Different employee has different categories of access. The employees in the company are restricted to particular resource utilization and Administration has the complete access to review all employee's work. Similarly in AWS, the root user
5 min read
What Is AWS IAM Policy?
In this article, we will learn about identity and access management (IAM) policies in Amazon Web Services. IAM in AWS is a free service that allows the owner of an AWS account known as the root to grant other users and services access to his account's resources on his behalf. The policies in Iam allow the admin to have fine-grained control over his
5 min read
How To Create AWS IAM Roles Using Terraform?
Terraform is an IAAC tool which is used provision infrastructure . Here in this guide i will first discuss what is terraform . Then i will discuss what is IAM Role and in which scenarios we should use IAM Role . Then i will walk you through the different steps to create an IAM Role for an EC2 service having CloudWatch and SNS full access policy . W
5 min read
Using AWS-CDK (Java) to automate creation of IAM User
In this document, we will demonstrate how to set up aws-cdk in Windows (with additional helpful links provided for MAC or Linux users). Using Java as the coding language, we will build and deploy changes to create a new IAM user. Most of the operations will be automated using code with minimal interaction on the AWS UI for initial setup. What is aw
8 min read
Amazon Web Services - Using Single SSH Key For all AWS Regions
Secure Shell also known as SSH is a cryptographic network protocol that helps secure network services over an unsecured network. It securely helps users to log in to a server with SSH than using a password alone. SSH keys are nearly impossible to decipher by brute force alone unlike passwords. In this article, we are going to look into how users ca
2 min read
Amazon Web Services - Creating a User Pool in AWS Cognito
A User pool in AWS Cognito is a user directory, which helps users to sign in to your web or mobile app through AWS Cognito. Users can also sign in through other social platforms like Google, Facebook, Amazon, or Apple. It doesn't matter users can directly sign in or use a third-party authentication, all these users in the User pool have a profile d
3 min read
Amazon Web Services - Setting Up an AWS Account
Amazon web services is a cloud service platform that provides on-demand computational services, databases, storage space, and many more services. AWS allows its user to choose products from its wide variety of services and use them on-demand with no upfront payment for most of the services. Individually an AWS service may lack some functionality bu
4 min read
Amazon Web Services - Receive Customized Notification for a Specific AWS Service Event Types Trigger
Sometimes users need to receive an email response with a custom notification for a specific AWS service event type trigger. In this article we are going to look into how can you receive customized notifications using an input transformer in AWS CloudWatch. To do so follow the below steps: Step 1: After logging into the AWS management console naviga
2 min read
AWS (Amazon Web Services) SNS VS SQS
Are you confused between the AWS SNS and AWS SQS? If yes, here is the best guide to help you. This insightful article covers complete details on the comparison between the AWS SNS and AWS SQS. By the end of this guide, you will be able to easily find what AWS Tool is best suited for your business. IntroductionThe messaging service plays an importan
8 min read
Amazon Web Services (AWS) Transit Gateway VS VPC Peering
Are you looking forward to enhancing the connectivity of your Cloud Infrastructure using AWS? If it is so, you have landed in the right place. This article covers detailed AWS Transit Gateway and VPC Peering, their advantages, use cases, and differences. By the end of this article, you will be easily able to decide which AWS networking solution bes
8 min read
AWS (Amazon Web Services) RDS vs Aurora
Do you need help in choosing the right AWS database for your application? Here is the solution for you. This article resolves all your queries about AWS RDS and Aurora, advantages, use cases, and differences between them. Reading this article till the end will help you to choose the appropriate database for your application development requirements
7 min read
Making A Text2Speech Application In Android Using Amazon Web Services (AWS Polly)
A text-to-speech application is an application that converts text into life-like speech. In this project, we will be making use of Android Studio IDE for our front end and Amazon Web Services (AWS) as our back end. AWS provides a lot of services including AWS Polly which we will be using in this project. AWS Polly uses deep learning technologies to
8 min read
Amazon Web Services (AWS) - Free Tier Account Set up
Amazon Web Service (AWS) is the world’s most comprehensive and broadly adopted cloud platform, offering over 200 fully featured services from data centers globally. Millions of customers, including the fastest-growing startups, largest enterprises, and leading government agencies, are using AWS to lower costs, become more agile, and innovate faster
5 min read
Architecture of Identity Access Management in Cloud Computing
Pre-requisite: IAM Identity Access Management is used by the root user (administrator) of the organization. The users represent one person within the organization, and the users can be grouped in that all the users will have the same privileges to the services. Shared Responsibility Model for Identity Access ManagementCloud Service Provider (CSP)In
3 min read
Amazon Web Services - Restricting S3 Access Only From CloudFront
In this article, we will look into how to restrict access to Simple Storage Service (S3) from CloudFront only. When developers are using S3 REST API endpoint as the origin to CloudFront, they can restrict access to S3 from CloudFront only by setting up the Origin Access Identity(OAI). This is a special CloudFront user, which they will associate wit
2 min read
Amazon Web Services - Managing Invalid Keys in Key Management System
In this article, we will look into how to resolve an error indicating that a "customer master key policy statement contains one or more invalid principles”. When we create identities within AWS Identity and Access Management (IAM). We often give them friendly names like developer, some name or administrator. IAM entities can also be identified with
2 min read
How to Create IAM roles for Amazon EC2?
In this article, we will cover how we can easily create an IAM role use it with an EC2 instance, and provide the required permissions with the S3 policies. These IAM Roles are the identities that we are creating in our account so that we can provide specific permissions to the users. So these Roles provide us the temporary credentials of security f
7 min read
Amazon Web Services - Configuring Amazon S3 Event Notifications
The Amazon S3 notification feature enables you to receive notifications when a certain event occurs inside your bucket. To get notifications, first, add a notification configuration that reads the event you want Amazon S3 to publish and the destinations where Amazon S3 will send the notifications. This configuration is stored in the notification su
5 min read
Amazon Web Services - Amazon S3 Notifications to SNS
In this article, we will see how the Amazon S3 bucket publishes notifications to SNS topics on object creation events. An object that creates an event is of four types. They are Put, Post, Copy, Multipart Upload, Remove, Replicate and Restore. Thus, whenever any of the event occur in our S3 bucket, it will publish a notification to a topic and the
3 min read
Amazon Web Services - Introduction to Amazon CloudWatch Synthetics
In this article, we will get an introduction to Amazon Cloudwatch Synthetics. With this feature, you can create different kinds of Canaries to continually verify your user experience even when you don't have traffic, monitor and test for unusual behavior, and trace issues to their source for faster resolution. Let's start by navigating to CloudWatc
3 min read
Article Tags :