AWS IAM Essentials

Master AWS IAM for the CLF-C02 exam — users, groups, roles, policies, MFA, CLI, and SDK explained simply with key exam tips you can't afford to miss.

Mastering AWS IAM

IAM is one of the most frequently tested topics on the CLF-C02 exam. This guide covers the core components of IAM, its permission model, and the security tools you need to know.

---

What Is IAM?

IAM (Identity and Access Management) is the AWS service that securely controls access to AWS resources. It determines who can do what within your AWS environment.

IAM manages three primary concepts:

Users: Individual identities interacting with AWS services Groups: Collections of users sharing common permissions Roles: Temporary permissions assigned to AWS services or applications

IAM is a global service with no additional cost. There is no need to select a specific region when using it.

---

Users and Groups

| | Description | |--|--| | IAM User | Unique identity with credentials (username/password, access keys) | | IAM Group | Logical grouping of users for simplified permission management |

There are a few important rules about how users and groups relate. A user does not have to belong to any group. A single user can belong to multiple groups simultaneously. However, groups cannot contain other groups — nesting is not allowed.

---

Permissions and Policies

Permissions are defined using JSON policy documents that specify which actions are allowed or denied.

Policy Structure

| Element | Description | |---------|-------------| | Version | Policy language version (always 2012-10-17) | | Effect | Allow or Deny | | Action | AWS service action to allow or deny | | Resource | Target AWS resource (ARN) |

When designing policies, follow the Principle of Least Privilege — grant only the permissions required for the task at hand. This significantly reduces the risk of unauthorized access.

Policy Types

| Type | Description | |------|-------------| | AWS Managed Policies | Pre-built reusable policies provided by AWS | | Customer Managed Policies | Custom policies created and maintained by you | | Inline Policies | Policies directly embedded in a single user, group, or role |

---

IAM Roles

IAM Roles allow AWS services to access other AWS services without storing long-term credentials in code. This is a significantly safer approach than embedding access keys directly in application code.

Common use cases include:

An EC2 instance accessing S3 buckets A Lambda function reading from or writing to DynamoDB

For any application running on AWS, using an IAM Role instead of an IAM User is the recommended approach. It eliminates the risk of long-term credentials being exposed.

---

MFA (Multi-Factor Authentication)

MFA adds a second layer of security on top of a password. Even if a password is stolen, MFA prevents unauthorized access to the account.

MFA Devices in AWS

| Type | Description | |------|-------------| | Virtual MFA | Smartphone apps like Google Authenticator or Authy (TOTP) | | Hardware MFA | Physical token devices such as Gemalto | | U2F Security Key | USB-based security keys |

MFA should always be enabled on the root account and on any IAM users with elevated privileges.

---

Password Policy

AWS IAM allows you to configure the following password rules for your account:

Minimum password length Required character types (uppercase, lowercase, numbers, symbols) Password reuse prevention Expiration period (for example, every 90 days)

---

Three Ways to Access AWS

| Method | Description | |--------|-------------| | AWS Management Console | Web-based GUI | | AWS CLI | Terminal commands for automation | | AWS SDK | Programmatic access via languages like Python and JavaScript |

CLI Example

SDK Example (Python boto3)

Both the CLI and SDK require Access Keys (Access Key ID and Secret Access Key). These keys should never be shared or hardcoded directly in your source code.

---

IAM Security Tools

| Tool | Purpose | |------|---------| | IAM Credential Report | Lists all IAM users and their credential status — useful for auditing | | IAM Access Advisor | Shows when permissions were last used, helping identify and remove unnecessary access | | IAM Policy Simulator | Tests and validates policies before applying them |

Use the Credential Report for regular security audits. The Access Advisor is especially helpful for maintaining the Principle of Least Privilege by surfacing permissions that are no longer in use.

---

Shared Responsibility Model

| AWS Responsibility | Customer Responsibility | |-------------------|------------------------| | Protect IAM service infrastructure | Manage users, groups, and roles | | Ensure service availability | Set strong password policies and enable MFA | | Provide AWS managed policies | Apply least privilege and conduct regular audits |

---

IAM Best Practices

Minimize root account usage. Use IAM users for day-to-day operations. Apply the Principle of Least Privilege consistently. Enable MFA on the root account and all administrative IAM users. Use IAM Roles for applications instead of hardcoding access keys. Rotate access keys on a regular schedule. Audit permissions periodically using the Credential Report and Access Advisor.

---

Key Points for the Exam

IAM is a global service — no region selection is needed A policy is a JSON document — the key elements are Effect, Action, and Resource Groups cannot be nested inside other groups MFA is the last line of defense if a password is compromised IAM Role is the safe way to grant permissions to AWS services Credential Report is the auditing tool; Access Advisor identifies unused permissions

Back to blog list