Can groups be nested?
No
Policy document format
JSON
Policies aka
Permissions
IAM Policy:
SID
Effect
Principal
Action
Resource
Optional ID number
Allow or Deny access
Account/role it applies to
List of actions allowed or denied
How can users access AWS?
Management console
CLI (w/ access keys)
SDK (w/ access keys)
IAM Roles
Used by services to perform actions
IAM Roles
Specific permissions for short durations
Assume a role
How long do IAM roles last?
Temporary credentials per session
IAM Access Advisor
Shows service permissions granted to a user and when services were last accessed
IAM Credentials Report
Lists accounts users and status of credentials