AWS IAM helps you control access to your AWS services and resources
AWS IAM (Identity and Access Management) is a web service that helps you securely control access to AWS services and resources.
The service allows you to create and manage AWS users and groups within your account, and use permissions to permit or deny their access to AWS resources. A user is an identity (within an AWS Account) with unique security credentials that can be used to access AWS Services.
Without IAM, organizations with multiple users and systems would be forced to either create multiple AWS accounts, each with its own billing and subscriptions to AWS products, or employees would all have to share the security credentials of a single AWS account. There would be no way to control the tasks a particular user or system could perform and which AWS resources they might use.
Limiting user access with AWS IAM:
With IAM, you can control who can access which resources. For example, you can create individual users, each with their own user name, password, and access keys. You can assign them unique authority over precisely the resources and services they need.
Whenever a person or application communicates with an AWS resource, they are asked for security credentials. These credentials are helpful in classifying who is making the call and whether or not to allow the requested access.
But why not just rely on a single identity? Whenever you log into your AWS account using your email address and password, you get full access to all your account’s resources. Because that kind of access is very difficult to properly control, AWS suggests that you use only IAM credentials for your everyday interactions with AWS, and lock away your account credentials.
AWS IAM allows you to:
1. Create individual IAM users and groups to assign permissions to IAM users
You could, for example, set up an Administration Group as soon as you create your account. You could then add to it all the IAM users who will need administrator rights to your account. Now, they – and only they – will have full rights over your account resources.
2. Enable AWS Multi-Factor Authentication (AWS MFA) for privileged users
To help prevent fraudulent access, AWS recommends that you use multi-factor authentication (MFA) in addition to your AWS account’s email address and password. A device (like a smartphone) in the possession of MFA users can be configured to generate a unique authentication code and provide extra security.
3. Request temporary security credentials
For users or apps requiring on-demand access to your services and resources, AWS IAM allows you to offer one-off permissions, further limiting your exposure to risk.
4. Force your users to choose strong passwords
You can require that your users create passwords of a defined strength (minimum length, non-alphabetic characters, etc.) and that they change them regularly.
5. Rotate credentials regularly and remove unnecessary credentials
Remove unused IAM user credentials (i.e., passwords and access keys). For example, an IAM user that is used exclusively for an application does not need a password (passwords are necessary only to sign in to AWS websites). Similarly, if a user does not and will never use access keys, there’s no reason for the user to have them.
6. Use AWS IAM roles for applications running on Amazon EC2 instances
In order to access other AWS services, applications that run on an Amazon EC2 instance need credentials. Here IAM plays a vital role in providing these credentials to the applications in a secure way. A role is an entity that has its own set of permissions, but that isn’t a user or group.
AWS IAM dynamically provides temporary credentials to an EC2 instance, and these credentials are automatically rotated for you.
7. Use policies for extra security
You can apply permissions to an IAM principal entity (an IAM user, group or role) by attaching a custom policy to the principal entity.
For example, you can write conditions to specify a range of allowable IP addresses that a request must come from, or specify that a request is allowed only within a specified date or time range. You can also set conditions that require the use of SSL or MFA (multi-factor authentication). For example, you can require that a user has authenticated with an MFA device in order to be allowed to terminate an Amazon EC2 instance.
You can attach multiple policies to a principal entity, and each policy can contain multiple permissions.
AWS IAM user management
One cannot set usage quotas on IAM users, as all limits apply to the AWS account as a whole. So for example, if your AWS account has a limit of twenty Amazon EC2 instances, any IAM user with EC2 permissions will be able to launch up to that limit (assuming that there are no other instances associated with other account users).
While there is no limit to the number of AWS IAM roles you can assume, you can only act as one IAM role when making requests to AWS services. You are however limited to a maximum of 250 IAM roles for a single account. If you need more roles, submit an IAM limit increase request form with your use case and your AWS IAM role increase will be considered.
Protect your AWS environment by using the high-level security of AWS IAM. It costs nothing extra and greatly strengthens the value of your username and password credentials.
If you want to get a jump start on IAM, check out Cloud Academy’s Overview of AWS Identity & Access Management (IAM) course.
Top 5 AWS Salary Report Findings
At the speed the cloud tech space is developing, it can be hard to keep track of everything that’s happening within the AWS ecosystem. Advances in technology prompt smarter functionality and innovative new products, which in turn give rise to new job roles that have a ripple effect on t...
New on Cloud Academy: Red Hat, Agile, OWASP Labs, Amazon SageMaker Lab, Linux Command Line Lab, SQL, Git Labs, Scrum Master, Azure Architects Lab, and Much More
Happy New Year! We hope you're ready to kick your training in overdrive in 2020 because we have a ton of new content for you. Not only do we have a bunch of new courses, hands-on labs, and lab challenges on AWS, Azure, and Google Cloud, but we also have three new courses on Red Hat, th...
Cloud Academy’s Blog Digest: Azure Best Practices, 6 Reasons You Should Get AWS Certified, Google Cloud Certification Prep, and more
Happy Holidays from Cloud Academy We hope you have a wonderful holiday season filled with family, friends, and plenty of food. Here at Cloud Academy, we are thankful for our amazing customer like you. Since this time of year can be stressful, we’re sharing a few of our latest article...
Google Cloud Platform Certification: Preparation and Prerequisites
Google Cloud Platform (GCP) has evolved from being a niche player to a serious competitor to Amazon Web Services and Microsoft Azure. In 2019, research firm Gartner placed Google in the Leaders quadrant in its Magic Quadrant for Cloud Infrastructure as a Service for the second consecuti...
New Lab Challenges: Push Your Skills to the Next Level
Build hands-on experience using real accounts on AWS, Azure, Google Cloud Platform, and more Meaningful cloud skills require more than book knowledge. Hands-on experience is required to translate knowledge into real-world results. We see this time and time again in studies about how pe...
New on Cloud Academy: AWS Solution Architect Lab Challenge, Azure Hands-on Labs, Foundation Certificate in Cyber Security, and Much More
Now that Thanksgiving is over and the craziness of Black Friday has died down, it's now time for the busiest season of the year. Whether you're a last-minute shopper or you already have your shopping done, the holidays bring so much more excitement than any other time of year. Since our...
Understanding Enterprise Cloud Migration
What is enterprise cloud migration? Cloud migration is about moving your data, applications, and even infrastructure from your on-premises computers or infrastructure to a virtual pool of on-demand, shared resources that offer compute, storage, and network services at scale. Why d...
6 Reasons Why You Should Get an AWS Certification This Year
In the past decade, the rise of cloud computing has been undeniable. Businesses of all sizes are moving their infrastructure and applications to the cloud. This is partly because the cloud allows businesses and their employees to access important information from just about anywhere. ...
AWS Regions and Availability Zones: The Simplest Explanation You Will Ever Find Around
The basics of AWS Regions and Availability Zones We’re going to treat this article as a sort of AWS 101 — it’ll be a quick primer on AWS Regions and Availability Zones that will be useful for understanding the basics of how AWS infrastructure is organized. We’ll define each section,...
Application Load Balancer vs. Classic Load Balancer
What is an Elastic Load Balancer? This post covers basics of what an Elastic Load Balancer is, and two of its examples: Application Load Balancers and Classic Load Balancers. For additional information — including a comparison that explains Network Load Balancers — check out our post o...
Advantages and Disadvantages of Microservices Architecture
What are microservices? Let's start our discussion by setting a foundation of what microservices are. Microservices are a way of breaking large software projects into loosely coupled modules, which communicate with each other through simple Application Programming Interfaces (APIs). ...
Kubernetes Services: AWS vs. Azure vs. Google Cloud
Kubernetes is a popular open-source container orchestration platform that allows us to deploy and manage multi-container applications at scale. Businesses are rapidly adopting this revolutionary technology to modernize their applications. Cloud service providers — such as Amazon Web Ser...