IAM

Introduction

  • Identity and Access Management (IAM) enableing control access to AWS services and resources

  • Can create and manage AWS users and groups, and use permissions to allow and deny their access to AWS resources

  • A global (Not Regional) service

Feature

  • Providing

    • Centralized control

    • Shared access to AWS account

    • Granular permissions

    • Identity Federation (ex. to a SAML IdP)

      • Create a SAML provider in IAM and create IAM role that establishes a trust relationship between IAM and the IdP that identifies the IdP as a principal (trust entity) for purposes of federation.

    • Multifactor Authorization (MFA)

    • Providing temporary access for users, devices, services

    • Can set up custom password policy (ex: password rotation)

    • Support PCI DSS compliance

  • Composition

  • Evaluaiton logicsarrow-up-right

    • Authenticates the principal.

    • Determines which policy to apply to the request.

    • Evaluates the policy types and arranges an order of evaluation.

    • Processes the policies against the request context to determine if it is allowed.

Determining whether a request is allowed or denied within an account

Related Service

  • Access Advisor - See permissions granted and last access time

  • Access Analyzer - Analyze resources that are shared with external entity

Last updated