DEV Community

Cover image for AWS: IAM, Regions, Availability Zones, and the Shared Responsibility Model
Fahad Khalid
Fahad Khalid Subscriber

Posted on

AWS: IAM, Regions, Availability Zones, and the Shared Responsibility Model

The Beginner Problem

One of the most common mistakes new AWS users make is launching resources before understanding three foundational concepts:

  • Who is allowed to do something? → IAM
  • Where are resources running? → Regions and Availability Zones
  • Who is responsible for security? → Shared Responsibility Model

A beginner might create an EC2 instance, upload files to Amazon S3, and then realize:

  • They accidentally used administrator permissions everywhere.
  • They deployed resources in the wrong Region.
  • They assumed AWS automatically backs up or secures everything.
  • They cannot find a resource because they're viewing a different Region.

These mistakes appear simple, but they are exactly the type of concepts tested heavily in:

  • AWS Certified Solutions Architect – Associate (SAA)
  • AWS Certified Machine Learning Engineer – Associate (MLA-C02)
  • AWS Professional-level architecture and security domains

In this hands-on article, you'll build foundational AWS knowledge through practical implementation instead of memorization.


Learning Objectives

By the end of this exercise you should understand:

  • IAM users, groups, permissions, and policies
  • Least privilege access
  • AWS Regions and Availability Zones (AZs)
  • High availability fundamentals
  • AWS Shared Responsibility Model
  • AWS account security best practices
  • How these concepts fit into real cloud architectures

Where These Concepts Fit in Real Architecture

Before opening the console, it helps to understand where these concepts fit.

A simple AWS application may look like this:

User
   |
   v
IAM Authentication & Authorization
   |
   v
VPC
   |
   +---- EC2 Instance (AZ-A)
   |
   +---- EC2 Instance (AZ-B)
   |
   +---- Amazon S3 Bucket
   |
   +---- RDS Database
Enter fullscreen mode Exit fullscreen mode

Architecture Diagram Description

Create an architecture image containing:

  • One AWS Region
  • Two Availability Zones within that Region
  • One EC2 instance in each Availability Zone
  • One Amazon S3 bucket shared across the Region
  • One IAM user accessing AWS services
  • Labels showing:
    • IAM controls access
    • AZs improve availability
    • Regions determine geographic placement
    • AWS and customer share security responsibilities

Understanding IAM

What Is IAM?

AWS Identity and Access Management (IAM) is the AWS service used to control who can access AWS resources and what actions they can perform.

Think of IAM as the security guard for your AWS account.

IAM answers three questions:

  1. Who are you?
  2. What resources can you access?
  3. What actions are you allowed to perform?

Without IAM, every user would effectively have administrator permissions, which creates major security risks.


Real-World Example

Imagine a startup team:

Team Member Access Needed
Developer Amazon EC2
Data Analyst Amazon S3
Security Engineer IAM
Intern Read-only access

Giving all of them AdministratorAccess would violate AWS security best practices.

Instead, IAM allows organizations to grant only the permissions required for each role. This principle is known as least privilege.


Understanding Regions and Availability Zones

AWS infrastructure is organized into Regions and Availability Zones.

These concepts are frequently tested in AWS certification exams because they directly affect:

  • Availability
  • Resilience
  • Disaster recovery
  • Compliance
  • Cost management

What Is a Region?

A Region is a geographic AWS location.

Examples include:

  • US East (N. Virginia)
  • US East (Ohio)
  • Europe (Frankfurt)
  • Asia Pacific (Mumbai)

When selecting a Region, consider:

  • User location
  • Regulatory requirements
  • Available AWS services
  • Latency requirements

Example

If your customers are primarily in Pakistan and India, you may choose:

ap-south-1 (Mumbai)
Enter fullscreen mode Exit fullscreen mode

to reduce latency compared to a North American Region.


What Is an Availability Zone?

An Availability Zone (AZ) is an isolated AWS facility within a Region.

Examples:

us-east-1a
us-east-1b
us-east-1c
Enter fullscreen mode Exit fullscreen mode

Each Availability Zone is designed to operate independently.

If one Availability Zone experiences problems:

  • Applications running in another AZ may continue operating.
  • High availability architectures remain functional.

Why Multiple Availability Zones Matter

Single-AZ deployment:

EC2
 |
AZ-A
Enter fullscreen mode Exit fullscreen mode

If AZ-A fails:

Application Unavailable
Enter fullscreen mode Exit fullscreen mode

Multi-AZ deployment:

EC2 (AZ-A)
     |
Load Balancer
     |
EC2 (AZ-B)
Enter fullscreen mode Exit fullscreen mode

If one AZ fails:

Traffic continues through surviving AZ
Enter fullscreen mode Exit fullscreen mode

This is a core AWS high-availability pattern.


Understanding the Shared Responsibility Model

One of the most important AWS concepts is understanding who is responsible for what.

Many beginners incorrectly assume:

“AWS manages security, so I'm automatically protected.”

This is false.

AWS security follows a Shared Responsibility Model.


AWS Responsibilities

AWS is responsible for security OF the cloud, including:

  • Physical data centers
  • Physical network infrastructure
  • Power systems
  • Cooling systems
  • Hardware
  • Virtualization infrastructure

AWS manages and protects the underlying cloud infrastructure.


Customer Responsibilities

Customers are responsible for security IN the cloud, including:

  • IAM permissions
  • User management
  • Data protection
  • Application security
  • Operating system patching on EC2
  • Security Groups
  • Encryption configuration

Certification Exam Example

Question:

An EC2 instance is compromised because security updates were never installed.

Who is responsible?

Answer: Customer

Reason:

For Amazon EC2, customers are responsible for managing and patching the guest operating system.


Prerequisites

Before beginning:

  • AWS account
  • Access to AWS Management Console
  • MFA enabled on the root account (recommended)
  • Modern web browser
  • Basic cloud computing familiarity

Important: AWS updates the console regularly. If your interface differs from the screenshots or instructions shown here, verify the latest workflow using the official AWS documentation.


Hands-On Lab

Part 1: Create an IAM User

Certification Concepts

SAA

  • Identity and Access Management
  • Security Best Practices
  • Least Privilege

MLA-C02

  • Secure access to machine learning resources

Step 1: Open IAM

Navigate to:

AWS Console
→ IAM
→ Users
Enter fullscreen mode Exit fullscreen mode

Why This Step Matters

Users represent individual human identities.

AWS recommends avoiding daily use of the root account.


Step 2: Create a New User

Select:

Create User
Enter fullscreen mode Exit fullscreen mode

Example username:

student-user
Enter fullscreen mode Exit fullscreen mode

Enable:

Provide user access to AWS Management Console
Enter fullscreen mode Exit fullscreen mode

Why This Option Matters

This creates a separate identity rather than sharing root credentials.

This follows AWS security best practices.


Step 3: Assign Permissions

Choose:

Attach policies directly
Enter fullscreen mode Exit fullscreen mode

Select:

ReadOnlyAccess
Enter fullscreen mode Exit fullscreen mode

Why This Policy?

ReadOnlyAccess allows a user to:

  • View resources
  • Explore the account
  • Learn AWS safely

It prevents:

  • Resource deletion
  • Infrastructure modification
  • Administrative changes

This demonstrates least privilege access.


Step 4: Review and Create

Review:

  • Username
  • Console access
  • Attached permissions

Click:

Create User
Enter fullscreen mode Exit fullscreen mode

Save:

  • Sign-in URL
  • Username

You will use them later for testing.


Part 2: Explore AWS Regions

Certification Concepts

SAA

  • Global Infrastructure
  • Regional Design
  • Workload Placement

Step 1: Locate the Region Selector

In the AWS Console, locate the Region selector in the upper-right corner.

Examples:

us-east-1
us-west-2
eu-west-1
ap-south-1
Enter fullscreen mode Exit fullscreen mode

Step 2: Switch Between Regions

Move from one Region to another.

Observe:

  • EC2 instance lists change
  • VPC configurations change
  • Resource inventories change

Key Lesson

Most AWS resources are Regional.

Resources created in one Region do not automatically appear in another Region.


Part 3: Explore Availability Zones

Certification Concepts

SAA

  • Fault Tolerance
  • Availability
  • Resilience Design

Step 1: Open EC2

Navigate to:

EC2
→ Launch Instance
Enter fullscreen mode Exit fullscreen mode

You do not need to launch an instance.

You are only exploring the configuration options.


Step 2: Review Network Placement

Locate:

Availability Zone
Enter fullscreen mode Exit fullscreen mode

Examples:

us-east-1a
us-east-1b
us-east-1c
Enter fullscreen mode Exit fullscreen mode

Why This Matters

Workloads distributed across multiple Availability Zones are more resilient than workloads running in a single AZ.

This principle is used heavily in production architectures.


Part 4: Apply the Shared Responsibility Model

Certification Concepts

SAA

  • Security Design
  • Operational Excellence

Professional Certifications

  • Governance
  • Risk Management
  • Compliance

Scenario

You launch:

Amazon EC2
Enter fullscreen mode Exit fullscreen mode

Now ask:

Who secures what?


AWS Secures

  • Physical servers
  • Network facilities
  • Storage hardware
  • Data center operations

You Secure

  • Application code
  • IAM permissions
  • Operating system updates
  • Security Groups
  • Credentials
  • Data access controls

Validation and Testing

Test 1: IAM Login

Log in using the newly created IAM user.

Expected Result:

Login succeeds
Enter fullscreen mode Exit fullscreen mode

Test 2: Attempt Administrative Actions

Attempt:

Create a new IAM policy
Enter fullscreen mode Exit fullscreen mode

Expected Result:

Access Denied
Enter fullscreen mode Exit fullscreen mode

Reason:

ReadOnlyAccess does not permit administrative changes.


Test 3: Switch Regions

Move between Regions.

Expected Result:

Different resources appear
Enter fullscreen mode Exit fullscreen mode

Test 4: Identify Availability Zones

Locate at least two AZs within your selected Region.

Expected Result:

Multiple AZs available
Enter fullscreen mode Exit fullscreen mode

Test 5: Shared Responsibility Review

For an EC2 deployment, identify customer responsibilities.

Expected Answers:

  • IAM configuration
  • Operating system patching
  • Security Group configuration

Troubleshooting

Case 1: Resources Cannot Be Found

Cause

Wrong Region selected.

Fix

Verify the Region selector.


Case 2: Access Denied Errors

Cause

IAM policy lacks required permissions.

Fix

Review attached policies and permissions.


Case 3: User Cannot Sign In

Cause

Console access was not enabled during user creation.

Fix

Edit the user settings and enable console access.


Case 4: Using Root Account for Everything

Cause

Common beginner mistake.

Fix

Create IAM users for daily activities.

Enable MFA on the root account.


Case 5: Assuming AWS Configures Security Automatically

Cause

Misunderstanding Shared Responsibility.

Fix

Review which responsibilities belong to AWS and which belong to customers.


Security Considerations

Follow these security practices:

  1. Enable MFA on privileged accounts.
  2. Avoid using the root user for routine work.
  3. Apply least privilege permissions.
  4. Remove unused users.
  5. Review permissions regularly.
  6. Use IAM roles where possible.
  7. Protect access keys.
  8. Monitor account activity.

Cost and Free Tier Awareness

This exercise primarily uses informational console activities.

However, always remember:

  • AWS pricing changes over time.
  • Free Tier eligibility changes.
  • Different Regions may have different pricing.

Before launching resources:

  • Review AWS Pricing
  • Review AWS Free Tier documentation
  • Confirm current pricing directly in AWS documentation

Never assume a resource is free because a tutorial says so.


Cleanup

Delete Test IAM User

Navigate to:

IAM
→ Users
→ student-user
→ Delete
Enter fullscreen mode Exit fullscreen mode

Verify Deletion

Confirm:

User no longer exists
Enter fullscreen mode Exit fullscreen mode

Delete Additional Resources

If you launched resources while experimenting, remove:

  • EC2 Instances
  • EBS Volumes
  • Elastic IP Addresses
  • Load Balancers

Review each service manually to ensure cleanup is complete.


Intermediate Extension Challenge

Create:

Developers Group
Enter fullscreen mode Exit fullscreen mode

Attach:

ReadOnlyAccess
Enter fullscreen mode Exit fullscreen mode

Then:

  1. Create multiple users.
  2. Add users to the group.
  3. Test permissions.

Skills Developed

  • IAM Groups
  • Permission Management
  • Least Privilege at Scale

Advanced / Professional Discussion

At the professional architect level, these concepts become organizational design decisions rather than basic AWS features.


Multi-Account Strategy

Many organizations separate:

Development
Testing
Production
Enter fullscreen mode Exit fullscreen mode

into different AWS accounts.

Benefits:

  • Better security boundaries
  • Easier auditing
  • Reduced operational risk

Multi-Region Architectures

Mission-critical applications often deploy across multiple Regions.

Benefits:

  • Disaster recovery
  • Geographic redundancy
  • Improved global user experience

Advanced IAM

Large organizations frequently adopt:

  • IAM Roles
  • Federation
  • AWS IAM Identity Center
  • Attribute-Based Access Control (ABAC)

to manage access at scale.


Compliance Considerations

Region selection may be driven by:

  • Data residency requirements
  • Regulatory obligations
  • Customer contracts
  • Disaster recovery requirements

These considerations commonly appear in AWS architecture certification exams.


References

AWS IAM Documentation: https://docs.aws.amazon.com/iam/
Getting Started with IAM: https://docs.aws.amazon.com/IAM/latest/UserGuide/getting-started.html
AWS Regions and Availability Zones: https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-regions-availability-zones.html
AWS Regions Documentation: https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-regions.html
AWS Shared Responsibility Model: https://aws.amazon.com/compliance/shared-responsibility-model/

Top comments (0)