IAM 101 Flashcards
Users
End Users
Groups
Collection of users under one set of permissions (or policies)
Roles
You create roles and assign them to AWS resources
Does IAM give you centralized control of your AWS account?
yes
Does IAM provide shared access to your AWS account?
yes
Does IAM provide granular permissions
yes
Does IAM provide identity federation to connect to Active Directory, Facebook, LinkedIN, etc.?
yes
Does IAM provide temporary access for users/devices if needed?
yes
Does IAM let you create & customize your own password rotation policy?
yes
Does IAM support PCI DSS compliance?
yes
Policies (Policy Documents)
document that defines one or more permissions. Attach policies to users, groups or roles
How do you apply a policy?
Attach policies to users, groups or roles
Policy Documents
Apply to users, groups, roles
made up of JSON
key-value pair: attribute and value (version:date) (effect:allow) (action:*)
Is IAM universal (global)
yes
it doesn’t apply to regions at this time
user, group or role is consistent across all regions
root account
the account created when first setting up your AWS account
Only account that has complete admin access by default