IAM Flashcards
Max number of IAM user identities?
5000
IAM roles are generally used for what purpose?
Unknown number or multiple principles not just one.
Multiple AWS users inside the same account.
Humans applications or services inside or outside of your account.
If you can’t identify the number of users or principles.
greater than 5000 users.
Access to resources on a temporary basis.
An IAM role represents what?
You the user.
Or
A level of access to something in an account.
A level of access to some thing in an account
An IAM user can be used for how many principles?
One or single
Two types of permissions policies for IAM roles are?
Trust and Permissions Policy
Trust Policy
Define which identities can assume a role.
AWS creates temporary security credentials for the IAM user assuming the role.
Permissions Policy
Specifies which resources the temporary credentials are allowed to access
STS: Secure Token Service
The operation used to assume the role to get security credentials
What user identity should be used for emergency temporary access to a resource
IAM Role
Business with 5500 users can assign IAM USER to each user?
No, use IAM Role (IAM USER has 5000 user max per account)
Web Identity Federation
Assigns IAM Roles to 3rd party Web Identities (Google, FaceBook, Twitter, etc)
Web Identity Federation scale?
Scales to hundreds of millions of users