Skip to main content
ServiceAmazonCurrent

AWS IAM

Also known as: AWS Identity and Access Management

Following adds this technology to your private workspace so related learning is easier to organise and revisit.

Technology explained

What is AWS IAM?

AWS Identity and Access Management controls authentication and authorisation for identities and resources in AWS accounts. This profile connects the concept to KBY's practical engineering guidance.

IAM evaluates identity policies, resource policies, permission boundaries, service control policies and session constraints to decide whether an API action is allowed. Users, roles and federated sessions should receive temporary, least-privilege access rather than long-lived broad credentials.

Primary purpose

Define and enforce who or what may perform actions against AWS resources.

Typical environments
AWS
Typical use cases
  • Managing user access to AWS resources
  • Enforcing least privilege
  • Configuring cross-account access
Technology map

Explore related technologies

Parent technology

Connected knowledge

6 resources for AWS IAM

Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.

Technology journey

Learn and operate with AWS IAM

Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.

Config Traps(4)

Recognise and avoid known failure modes.

Incident Runbooks(2)

Stabilise, recover and validate during incidents.