AWS IAM is the Identity and Access Management for Amazon Web Services

AWS IAM has the following Entities:

Policy in AWS is a document that defines one or more Permissions that is associated to a AWS user or Role.

  • JSON can be attached to any of the above.
  • Lists the specific APIs that is permitted for members of the Role (Think Scopes) (Permissions)
  • May have dynamic components such as are they on a VPN or time of day or network, or location.
  • May have a Implicit Deny which overrides any Allow permission.

