← AWS Cloud Practitioner: foundational decisions
02 / 6 · 20 MIN

Identity and least privilege

Grant task-appropriate access and reduce permanent credentials.

Understand the concept

IAM defines who or what may perform actions on resources. A role can provide temporary credentials to an application, avoiding long-lived keys in code. Least privilege requires actions, resources, and conditions matching actual work. Administrator access is not a generic application requirement.

Apply and decide

Protect the root user and restrict usage to tasks requiring it. For people, favor federation and strong authentication. Encryption in transit and at rest address different risks; key and permission management still matter. A provider compliance report does not prove your configuration meets all requirements.

Workplace application

For a reporting job, identify exact actions and objects it needs to read. Compare a limited role with a shared administrative credential. Confirm how the application receives credentials and how permissions are removed when the job is retired. A private subnet may limit paths but does not prove correct authorization. During handover, record who reviews access and where to obtain evidence of applied configuration.

IN PRACTICE

A job needs to read one specific bucket. A role with that access is more appropriate than distributing an administrator key.

Common pitfalls

Confusing roles with least privilege; a role can also have excessive access.

Related topics: Regions, zones, and resilience · Choose compute and data services

Take this idea with you

Give the right identity necessary access with controlled duration.

Create account

Reference: IAM security best practices · CLF-C02