Is a global service. User is single entity. Groups only contain users
iAM Users and Groups
Is attached a policy which defines the access control to a resource
Structure is Effect (Allow/Deny), Action(API calls), Resource (What resource access is allowed)
iAM Policies
Used by AWS services to access resources on users behalf. Permissions are assigned to the iAM role in order to do that.E.g. - EC2 instance roles, Lambda function roles, CloudFormation roles
iAM Role
iAM Role application