Authentication and Authorization—AWS Identity and Access Management

Ben Piper, David Clinton · 2019

This chapter provides an overview on Identity and Access Management (IAM) identities. It states that an identity represents an AWS user or a role. Roles are identities that can be temporarily assigned to an application, service, user, or group. Identities can also be federated. That is, users or applications without AWS accounts can be authenticated and given temporary access to AWS resources using an external service such as Kerberos, Microsoft Active Directory, or the Lightweight Directory Access Protocol (LDAP). Identities are controlled by attaching policies that precisely define the way they'll be able to interact with all the resources in your AWS account.

Read the paper · More papers on PaperTik