IAM Flashcards
IAM
IAM
Identity and Access Management
Create user accounts and control access
IAM
Root User best practice
IAM
Use only for managing IAM
IAM
Federation
IAM
Supports AD or SAML integration
IAM
MFA
IAM
Provides second factor for authentication
IAM
Best practice
IAM
Identities are given minimum access to complete tasks
IAM
IAM Credentials report
IAM
Lists users and status of their credentials
IAM
IAM Access Advisor
IAM
Shows service permissions and last accessed for user
IAM
User
IAM Identity
Account for single individual
IAM Identity
Group
IAM Identity
Permission management for users
IAM Identity
Group nesting
IAM Identity
May not nest groups
IAM Identity
Group membership
IAM Identity
Users can be in many groups, or none
IAM Identity
Role
IAM Identity
AWS Service can be granted access to another AWS Service
IAM Identity
IAM Policy
IAM
JSON document that defines permission for IAM Identity
IAM
Who can manage
IAM Policy
Can be managed by AWS or by customer
IAM Policy
IAM Policy structure (3)
IAM Policy
- Version
- ID
- Statement
IAM Policy
Statement structure (4/6)
IAM Policy
- SID
- Effect
- Principal
- Action
- Resource
- Condition
IAM Policy
Version
IAM Policy
Policy language version
IAM Policy
Id
IAM Policy
Unique Identifier
IAM Policy
Statement
IAM Policy
Defines what the policy does
IAM Policy
Sid
IAM Policy Statement
Statement Identifier
IAM Policy Statement
Effect
IAM Policy Statement
Alloy or deny
IAM Policy Statement
Principal
IAM Policy Statement
Identity that policy applies to
IAM Policy Statement
Action
IAM Policy Statement
List of allowed (or denied) Actions
IAM Policy Statement
Resource
IAM Policy Statement
List of resources the actions apply to
IAM Policy Statement
Condition
IAM Policy Statement
Optional conditions that determine when the policy applies
IAM Policy Statement
Identity and Access Management
Create user accounts and control access
IAM
IAM
IAM
Use only for managing IAM
IAM
Root User best practice
IAM
Supports AD or SAML integration
IAM
Federation
IAM
Provides second factor for authentication
IAM
MFA
IAM
Identities are given minimum access to complete tasks
IAM
Best practice
IAM
Lists users and status of their credentials
IAM
IAM Credentials report
IAM
Shows service permissions and last accessed for user
IAM
IAM Access Advisor
IAM
Account for single individual
IAM Identity
User
IAM Identity
Permission management for users
IAM Identity
Group
IAM Identity
May not nest groups
IAM Identity
Group nesting
IAM Identity
Users can be in many groups, or none
IAM Identity
Group membership
IAM Identity
AWS Service can be granted access to another AWS Service
IAM Identity
Role
IAM Identity
JSON document that defines permission for IAM Identity
IAM
IAM Policy
IAM
Can be managed by AWS or by customer
IAM Policy
Who can manage
IAM Policy
- Version
- ID
- Statement
IAM Policy
IAM Policy structure (3)
IAM Policy
- SID
- Effect
- Principal
- Action
- Resource
- Condition
IAM Policy
Statement structure (4/6)
IAM Policy
Policy language version
IAM Policy
Version
IAM Policy
Unique Identifier
IAM Policy
Id
IAM Policy
Defines what the policy does
IAM Policy
Statement
IAM Policy
Statement Identifier
IAM Policy Statement
Sid
IAM Policy Statement
Alloy or deny
IAM Policy Statement
Effect
IAM Policy Statement
Identity that policy applies to
IAM Policy Statement
Principal
IAM Policy Statement
List of allowed (or denied) Actions
IAM Policy Statement
Action
IAM Policy Statement
List of resources the actions apply to
IAM Policy Statement
Resource
IAM Policy Statement
Optional conditions that determine when the policy applies
IAM Policy Statement
Condition
IAM Policy Statement