AWS Builder Center
AWS IAM in 2 Minutes: Core Security Concepts

AWS IAM in 2 Minutes: Core Security Concepts

Identity and Access Management (IAM) controls who can authenticate and what they are authorized to do across your AWS resources.

Identity and Access Management (IAM) controls who can authenticate and what they are authorized to do across your AWS resources.

Core Components

  • Root User: Account owner with full access. Use only for account setup; lock away with MFA.
  • IAM User: Long-term identity for a human or legacy application.
  • IAM Group: Collection of users sharing identical permission sets (e.g., DevOps-Team).
  • IAM Role: Temporary security identity assumed by users, EC2 instances, or Lambda functions.
  • IAM Policy: JSON document defining explicit permissions (Allow / Deny).

Policy Evaluation Logic

$$\text{Implicit Deny (Default)} \longrightarrow \text{Explicit Deny (Overrides All)} \longrightarrow \text{Explicit Allow (Grants Access)}$$
  • Everything is Denied by default.
  • An Explicit Deny overrides any Allow.

Quick Diagnostic Exercises

  1. Deny Precedence: Attach both an Allow s3:* and a Deny s3:DeleteObject policy to a user. Verify deletion fails.
  2. Role Detachment: Strip an IAM Role from an EC2 server and attempt aws s3 ls from its terminal to watch credentials expire.
  3. MFA Condition: Add aws:MultiFactorAuthPresent: "true" to a policy condition and test CLI access without MFA.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article