CLF-C02 Beginner 25 min

IAM Users, Groups, and Roles

Master the core of AWS security: create users and groups, attach managed policies, create a role for EC2, and verify least-privilege access.

AWS IAMIAM PoliciesIAM Roles
Progress: 0 / 6 steps
Step 1
Explore the IAM Dashboard

1. AWS Console → search "IAM" → open IAM
2. Review the dashboard: users, roles, policies, account aliases
3. Note the security recommendations (MFA on root, etc.)

Tip: IAM is a global service — users and policies work in every region. No charge for IAM itself.
Step 2
Create an IAM Group with a Managed Policy

1. IAM → User groups → Create group
2. Group name: Developers
3. Attach policy: filter for "AmazonS3ReadOnlyAccess" and check it
4. Create user group

Tip: Attach policies to GROUPS, not individual users. New team members just join the group and inherit permissions.
Step 3
Create a User and Add to the Group

1. IAM → Users → Create user
2. User name: dev-alice
3. Select "Provide user access to the AWS Management Console" (optional for lab)
4. Set console password or autocreate
5. Next → Add user to group: Developers
6. Create user

Tip: Enable MFA for any user with console access. Long-term access keys should be avoided where roles are possible.
Step 4
Create a Role for EC2

1. IAM → Roles → Create role
2. Trusted entity: AWS service → EC2
3. Attach policy: AmazonS3ReadOnlyAccess
4. Role name: ec2-s3-readonly → Create role

json
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {"Service": "ec2.amazonaws.com"},
    "Action": "sts:AssumeRole"
  }]
}
Tip: Roles provide TEMPORARY credentials via the instance metadata service — no access keys stored on disk.
Step 5
Test Permissions with the Policy Simulator

1. IAM → Policy Simulator (left menu)
2. User: dev-alice
3. Service: S3, Actions: GetObject, PutObject
4. Run simulation: GetObject = allowed, PutObject = denied

This proves least privilege without logging in as the user.

Tip: The Policy Simulator is a free, exam-relevant tool: it shows exactly which statement in which policy allowed or denied an action.
Step 6
Clean Up

1. IAM → Users → dev-alice → Delete
2. IAM → User groups → Developers → Delete group
3. IAM → Roles → ec2-s3-readonly → Delete

Order matters: you cannot delete a group that still contains users.

Tip: Deleting IAM users removes their credentials immediately — API keys stop working within seconds.