# AWS IAM (Identity Access Management)

IAM (Identity Access Management) is a single AWS account that lets Root users manage all the users in the environment or the team. IAM helps with authorization and Authentication Access for the team. We can have different permissions and different groups with permission to manage the users.

*Note:* ***<mark>The user can create an IAM account with the same email as the one used to log in to the AWS Console Account. The user must switch from Root to IAM at the login window.</mark>***

![](https://lh4.googleusercontent.com/13COXjxDm81Wao6loriZSt86qeBZBCBc4AwI4g_vb6Sizcbc_r9ayu1lBbPKUhmpaGjCYorem--ficRsngARFyuQBGN3BIuIviiztvJS5E-Un0z48Imz14U_KBu3tjo4Pcwq9I1ubjHNJe2NkgK5BWQ3lrtO_bDIXKapzY7sImh24uRhcG8bkCe1TaE5Lg align="left")

* Once Logged in Navigate to the Search bar and Type **IAM** or **Identity Access Management**
    
* The user will be presented with the following dashboard, where users, groups, policies and etc can be managed.
    

![](https://lh4.googleusercontent.com/ljDoQkg8rjJct5nf31mnBAM7JIYL8TBzokDR7_dmX8f2lnqe1NzS03Obbo8zONyX0Z1f5fftDs3fFkvgRSoASrttVL7vkeKgNnEfwSyXngzToWl5q7woJ3iQwfSRZ7OLw4PVYj5MkubE__dP9DPhTaYom-6G337l46lieJVZB0e47VNv-I57pT_96CggrQ align="left")

## How to create Users in IAM

Users are known as entities, the purpose of creating users is to give the team or the environment access to the services in AWS. We can manage the users with the help of IAM.

* Click **Users** under **Access management**
    
* Click on **Add Users**
    

![](https://lh5.googleusercontent.com/YjCtyquoIEf2JZDorVDYSXo4Bko6FOjV77D3nnmDk2oVNLhOJm_MNjjMZ5thxDeyg5j6Kf1d7rWZ0nRJUYzVjuHGMsOj-4SixUC_ZikqT_-crYcOXuBOMOB1p7stBF8bbOL0XoqM_ImXGezigmaFiyROJMmintG1zQPSn2rGYoLzY4QZ4VlyooZWscI66w align="left")

* Add **user name**, under **Set user details.**
    

***(U1 is for demonstration purposes)***

* The user will have two ways to provide the access to the U1,
    
* Access Key - Programmatic Access (***User will connect using CLI, SDK, and other development tools to connect***)
    
* Password - AWS Management Console Access (***users will log in using AWS web console***)
    
* Let's use **Password - AWS Management console access.**
    

![](https://lh6.googleusercontent.com/fYGqkBaiW0l1a7BLJDDKCbYCYudurV6T_O3juQc6aGGOOhRyu8_Zmgn0njmxPt-LPV_8iQaOPGFLhNZFukwvjaKgsjdI6qZIBfH28Y9SzzHWQw4X1B2WV2yQupFTRHiqlFQDQm2QZoVP6IcN5BnCrAyIVPUWmGj8edNrZhoR_e92rr4sVckZdEaaDIby-A align="left")

* We can Add a user to the Group here or create a group for the user if it doesn't already exist.
    
* We can copy permissions from the existing user
    
* We can attach existing policies here as well
    
* We will just create a user at this time.
    
* Click on **Next: Tags Button**
    

![](https://lh4.googleusercontent.com/YrIeOfBEtIEl9tDjUhls2hkffzISCNR1RDrHLtG5C5_U3xFw1XbCJpJAKSbvCldabYnMk-xkvL_CnkbakLzd5gxXhbDRbFPorISOI-ZKuCFlgk0-3CCpsqZBtZFM0pzZOfRoEpp4u4jmVMaqUHwNEfhx7lwZxsuw5HaUI2yyAe4p17WyzQvpRXdv6cUphw align="left")

* **Add tags** is optional and it is used to organize, track and control access for the user. It could be the user's email, description, or job title.
    
* Click on the **Next: Review** button, to continue
    

![](https://lh5.googleusercontent.com/54RCE0-2GRu7I25i9IqPCNa43EtvWcgeudhIB4mhTwQUHmGNEaTJXOW2juGKByXefk6LucX7gkqPf4dkXhrEyZFY9W3K14K6ClJ9GcNSBEZpnLcd1thTA_GVVuYWIEvbkglhcGWg0qqF2ezpfrKp-USp1lWZFvrKPLq8L_64jto5Px8_BKAXLaIrkYZAoQ align="left")

* The user should Review all the inputted information and Click Create User.
    

![](https://lh3.googleusercontent.com/QUVNSYyRWo3jX4wCjWDTCopll8m5K3IVMGZWIOm8LvnIaHkEHEMUucm2rSHMZSviMJdQr_ecdCgOFOyTMT_xO5frZXObLqqqaSKhfUFvqc-Y--ptspZt3wi0U6-kHaQzud40tIL6I3_bi9QdsDPeq7sZITQ9vQa0D5OACdwmZXYRoZ48JvxKt0JPZLD_qg align="left")

* A user account will be created, You can either download the CSV and share it with the users successfully or Email the CSV file to the user.
    

# Creating Groups in IAM

A Group is known as an identity that has all the IAM

users in a single environment. The groups are used to specify the permissions for multiple users. The groups make permission to manage and apply to multiple users.

* To Create Groups Navigate to the left panel, under Access Management.
    
* Click on User groups.
    

![](https://lh5.googleusercontent.com/5gXI1lZaTw_PrbtmTr16pYmnSDx_uBvY-8RXwn7Ysc2Olp8QU_ZqPC77LdS8UWghzoXBoLr4vlSSg8xT7J46ihn3tifQFo2vNRiFOG_5yVLjQHEgSRr1BQ9rNwsffuE7AUyhdyAHbJMJnWUw0rdIJ95znB4AuAZBy8FDW6I4tz2juwW9O_GiAiJ3dKmNpw align="left")

* Give the group a specific name (ec2-access)
    
* You can also add users to the group, but it doesn’t have to be now.
    

![](https://lh4.googleusercontent.com/2A1XHCBHtVt2d1YGdvxCzV9dk1P40X3l7cc2daqlIMtHOWTAlf_-LdnWoE3eJ5reNvkyQPQ_6p39Nef-H8U3uSz34CVIgGJxvGIwIRdhsPifrCtprWGeEO04aub_LzNg6WgA0XroPTNELrAr1E_kRELBY1NNa64P9HCRAHk_b6Dk8COguZbAZTT8L3nhSQ align="left")

* Under Attach permission policies, there are many permissions to choose from, we need to create a group for users to give only read-only permissions.
    
* Select **AmazonGlacierReadOnlyAccess**
    
* Click **Create Group**
    

![](https://lh5.googleusercontent.com/qI3eOnVCJjEqcqctDQhYDuxMcDFs3FzaFT9zxDTF9d8NXjg8d_X_RH-Zet9Sv4BO-rC4fScCk8WltTKwHfabG4ymDYWhwmCZKuIDQVhAcKkw82xl_Yce7Is259IyiUP71rDapAKlqqlZ3h2Ubv8DyuGtp6FSx7yVn81jZ6JXoDX6pyCBBGOylOeFzC8O6g align="left")

* The group ecs-access is created under the group with the defined permissions.
    

![](https://lh4.googleusercontent.com/rXVUTZ-HtDdXgdaQ-YSREx97P7YO87RuJ6dpnMaZk4o5ywwkP3Ab-UhI0_FbAITxou1kJdYK6-L39P2-mJGBxJpBqQEKgiYsmnFlYNp3rUjKlQ6TDyOj-pNq4OUUp4tpgiiy6kMVUnnKEWiUpaYS36GyoqZmNbFpKhWFAV8Q7HJwgTNuJxcBbmARpJfpjg align="left")
