AWS Identity and Access Management (IAM)
Hands-On
Demo
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11579807/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11579818/pasted-from-clipboard.png)
Create User 1
developer1
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11579820/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11579825/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581382/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11579826/pasted-from-clipboard.png)
Review and create
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11579828/pasted-from-clipboard.png)
Console sign-in details
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580322/pasted-from-clipboard.png)
operations1
Create User 2
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581388/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581389/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580323/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580324/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581391/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580330/pasted-from-clipboard.png)
Review and create
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580331/pasted-from-clipboard.png)
Console sign-in details
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580333/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580349/pasted-from-clipboard.png)
Create user group
Developers
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581404/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581405/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580350/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581397/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580353/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581398/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580354/pasted-from-clipboard.png)
Create user group 2
Operations
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581402/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581406/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580356/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581407/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580358/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581409/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11582419/pasted-from-clipboard.png)
my-company-data-719246
Create bucket for Test Policy
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580399/pasted-from-clipboard.png)
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:ListAllMyBuckets",
"s3:GetBucketLocation"
],
"Resource": "arn:aws:s3:::*"
},
{
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject"
],
"Resource": [
"arn:aws:s3:::my-company-data-719246",
"arn:aws:s3:::my-company-data-719246/*"
]
}
]
}
Create Policy 1
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580400/pasted-from-clipboard.png)
DeveloperS3Access
Review and create
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580401/pasted-from-clipboard.png)
Create policy
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580403/pasted-from-clipboard.png)
Attach Policy to Developers Group
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580405/pasted-from-clipboard.png)
DeveloperS3Access
Attach permission policies to Developers
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580407/pasted-from-clipboard.png)
Create Policy 2
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:*",
"cloudwatch:*",
"s3:*"
],
"Resource": "*"
}
]
}
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580408/pasted-from-clipboard.png)
OperationsAccess
Review and create
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580409/pasted-from-clipboard.png)
Create policy
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580411/pasted-from-clipboard.png)
Attach Policy to Operations Group
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580413/pasted-from-clipboard.png)
OperationsAccess
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11582067/pasted-from-clipboard.png)
Fresh AWS Account - Only 2 Roles
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580541/pasted-from-clipboard.png)
Create role
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580543/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580544/pasted-from-clipboard.png)
AmazonS3ReadOnlyAccess
Add permissions
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580547/pasted-from-clipboard.png)
EC2S3ReadOnly
Role details
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580548/pasted-from-clipboard.png)
Create role
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581454/pasted-from-clipboard.png)
Difference between User Group and Role
Test
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580591/pasted-from-clipboard.png)
Login as developer1 - S3 View
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580562/pasted-from-clipboard.png)
Login as developer1 - EC2 View
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580584/pasted-from-clipboard.png)
Login as operations1 - S3 View
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580567/pasted-from-clipboard.png)
Login as operations1 - EC2 View
Clean Up
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580596/pasted-from-clipboard.png)
Delete Policies
DeveloperS3Access
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580598/pasted-from-clipboard.png)
Delete Policies
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580599/pasted-from-clipboard.png)
Delete Policies
OperationsAccess
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11580600/pasted-from-clipboard.png)
Delete Policies
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581079/pasted-from-clipboard.png)
Delete Role
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581080/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581081/pasted-from-clipboard.png)
Delete Users
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581082/pasted-from-clipboard.png)
![](https://s3.amazonaws.com/media-p.slid.es/uploads/2179736/images/11581436/pasted-from-clipboard.png)
Delete User Groups
🙏
Thanks
for
Watching
AWS IAM - Hands-On Demo
By Deepak Dubey
AWS IAM - Hands-On Demo
AWS IAM - Hands-On Demo
- 217