DEV Community

Gokul Kannan
Gokul Kannan

Posted on

AWS - IAM

Identity and Access Management

This Involves :
Users
Groups
permissions
Policies
Roles

The authentication and authorization in a cloud environment is managed through Identity and Access Management.

Lets take an example of a Small Tech Company which has multiple teams. Lets say a Dev Team, QA Team and a Network Team. Apart from these tech teams, we may have Management teams, HR team. To Manage the Authentication and Authorization for each of the members belonging to these teams would be a difficult job without proper management tool.

The IAM solves this problem. Here you would create Users as an identity and you can assign policies to control their authorization. Usually Users will be created and added to a particular group. So, that the policies can be attached to that group instead of attaching policies for each users could be tedious.

IAM (Identity and Access Management) is the AWS service that helps you

Create users
Manage permissions
Control access to AWS resources
Decide who can do what

"Who are you and what are you allowed to do?"

Imagine a company office.

People:

CEO
HR
Developers
Security Team
Interns

Resources:

Server Room
HR Files
Finance Records
Meeting Rooms

Purpose of IAM

The primary purpose of IAM is:

  1. Authentication

Verifying identity.

AWS asks:

"Who are you?"

Example:

Username + Password
Access Key + Secret Key
MFA Device

If identity is valid:

✅ User is authenticated

  1. Authorization

Determining permissions.

AWS asks:

"Now that I know who you are, what can you do?"

Examples:

Allowed:

Read S3 Bucket
Start EC2

Not Allowed:

Delete Production Database
Modify IAM Users

Authentication Authorization
Who are you? What can you do?
Identity verification Permission verification
Login process Access control
Username/password IAM Policy
Happens first Happens second

Shared Responsibility Model and IAM

What is Shared Responsibility?

AWS and Customer share security responsibilities.

Think of renting an apartment.

Landlord provides:

Building
Electricity
Water

Tenant manages:

Locking doors
Valuables
Visitors

Principle of Least Privilege:
Grant only the minimum permissions needed.
Give only the permissions needed to perform a task and nothing more.

Global Service means:

It is not tied to a specific AWS Region.

Example:

You create an IAM User in Mumbai.
Immediately available in:

Mumbai
Singapore
London
Virginia

Security Best Practices

  1. Never Use Root Account Daily
  2. MFA = Multi-Factor Authentication
  3. Use Roles Instead of Access Keys
  4. Rotate Credentials
  5. Regular Permission Reviews

Top comments (0)