IAM, ACCOUNTS AND AWS ORGANISATIONS Flashcards
Specifiy a list of resources to which the api actions apply
Resource
Optional – specifies the preliminary rules under which the policy grants permissions
Condition
List of actions or api that the policy allows or denies
Action
Refers to an IAM Identity you define
Principle
Only 2 possible values – allow, deny
Effect
First priority when evaluating policy logic
Explicit Denies
Second priority when evaluating policy logic
Explicit Allow
Third priority when evaluating policy logic
Default Deny
Remains unchanged even if you delete its associated IAM identity, It doesn’t have a strict one-to-one relationship to its associated IAM identity
Standalone Policy
Will be automatically be deleted if you delete its associated identity, Has a strict one-to-one relationship to its associated IAM identity
Inline Policy
Used for special or exceptional allows or denies
Inline Policies
The identity used for anything requiring long-term AWS access usually only a single principal
IAM User
Person or application that makes requests to IAM to interact with resources
Principal
Process where principal proves their identity
Authenticate
Uniquely identify resources within any AWS accounts
Amazon Resource Name (ARN)