Identity and Access Management
This Involves :
Users
Groups
permissions
Policies
Roles
The authentication and authorization in a cloud environment is managed through Identity and Access Management.
Lets take an example of a Small Tech Company which has multiple teams. Lets say a Dev Team, QA Team and a Network Team. Apart from these tech teams, we may have Management teams, HR team. To Manage the Authentication and Authorization for each of the members belonging to these teams would be a difficult job without proper management tool.
The IAM solves this problem. Here you would create Users as an identity and you can assign policies to control their authorization. Usually Users will be created and added to a particular group. So, that the policies can be attached to that group instead of attaching policies for each users could be tedious.
IAM (Identity and Access Management) is the AWS service that helps you
Create users
Manage permissions
Control access to AWS resources
Decide who can do what
"Who are you and what are you allowed to do?"
Imagine a company office.
People:
CEO
HR
Developers
Security Team
Interns
Resources:
Server Room
HR Files
Finance Records
Meeting Rooms
Purpose of IAM
The primary purpose of IAM is:
- Authentication
Verifying identity.
AWS asks:
"Who are you?"
Example:
Username + Password
Access Key + Secret Key
MFA Device
If identity is valid:
✅ User is authenticated
- Authorization
Determining permissions.
AWS asks:
"Now that I know who you are, what can you do?"
Examples:
Allowed:
Read S3 Bucket
Start EC2
Not Allowed:
Delete Production Database
Modify IAM Users
| Authentication | Authorization |
|---|---|
| Who are you? | What can you do? |
| Identity verification | Permission verification |
| Login process | Access control |
| Username/password | IAM Policy |
| Happens first | Happens second |
Shared Responsibility Model and IAM
What is Shared Responsibility?
AWS and Customer share security responsibilities.
Think of renting an apartment.
Landlord provides:
Building
Electricity
Water
Tenant manages:
Locking doors
Valuables
Visitors
Principle of Least Privilege:
Grant only the minimum permissions needed.
Give only the permissions needed to perform a task and nothing more.
Global Service means:
It is not tied to a specific AWS Region.
Example:
You create an IAM User in Mumbai.
Immediately available in:
Mumbai
Singapore
London
Virginia
Security Best Practices
- Never Use Root Account Daily
- MFA = Multi-Factor Authentication
- Use Roles Instead of Access Keys
- Rotate Credentials
- Regular Permission Reviews
Top comments (0)