Identity and Access Management
IAM controls authentication and authorization for AWS resources. Authentication answers who is requesting access; authorization answers what that identity is allowed to do.
Why it matters
AWS resources should not be openly accessible. IAM is the control layer that enforces least privilege.
How it works
Identity → policy evaluation → Allow/Deny decision → AWS service action.
Core Concept
IAM is used for identities, groups, policies, roles and authentication controls.
Use least privilege: grant only the permissions required for the task.
What you should remember
Key idea
IAM is used for identities, groups, policies, roles and authentication controls.
Key idea
Use least privilege: grant only the permissions required for the task.
Real-world example
Use a realistic cloud workload and focus on the responsibility of this AWS service.
Choose the service that matches the responsibility instead of forcing every workload into one resource.
Quick Test
1 QuestionWhat does IAM primarily control?