# AWS IAM: Users, Groups & Permissions — A Beginner-Friendly Guide 🔐☁️

When working with AWS, one of the first things we need to understand is who can access our AWS account and what they are allowed to do.

This is where IAM (Identity and Access Management) comes in.

IAM helps us create users, organize them into groups, and control their permissions.

### **What is AWS IAM?**

IAM stands for Identity and Access Management.

IAM is a global AWS service. Unlike services that are tied to a particular AWS Region, IAM users and groups are available across AWS.

The basic idea is:

*Users → Groups → Policies → Permissions*

### **Root User**

When we create an AWS account, a Root User is created automatically.

The root user has full access to the account, so it should be protected carefully.

The recommended approach is:

🔹Use the root user mainly for setting up the account.

🔹Don't use it for everyday activities.

🔹Don't share the root credentials.

🔹Create IAM users for regular access.

### **IAM Users 👤**

An IAM user represents an individual person in an organization.

For example, imagine an organization with six people:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/1fc97710-f02c-41a9-a32c-49cfbd45e26f.png align="left")

Each of these people can have an IAM user depending on their need to access AWS.

### IAM Groups 👥

When multiple users need similar permissions, we can organize them into groups.

For example:

Developers Group

*   Aryan
    
*   Bharat
    
*   Chetan
    

Operations Group

*   Deepak
    
*   Eshan
    

We also have an Audit Team Group containing:

*   Chetan
    
*   Deepak
    

This demonstrates an important IAM concept:

`A user can belong to multiple groups.`

Chetan belongs to both the Developers and Audit Team groups.

Deepak belongs to both the Operations and Audit Team groups.

At the same time, Farhan doesn't belong to any group.

That's possible in AWS, although the notes describe it as not being the best practice.

### Important rule

Groups can contain users, but groups cannot contain other groups.

So this is valid:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/01576735-5633-4e92-b24b-0defb8a1b798.png align="left")

But this is not:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/c3abf727-1772-49d0-8d52-ad67f4645a0d.png align="left")

### **IAM Policies 📜**

Users and groups can be assigned a JSON document called an IAM Policy.

A policy defines what a user or group is allowed to do.

For example, a policy can allow users to perform describe/read-type actions on:

*   EC2
    
*   Elastic Load Balancing
    
*   CloudWatch
    

A simplified example from the notes looks like this:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/4628de60-41ed-49bf-93b4-a0f57a19c14b.png align="left")

The important thing to understand at this stage isn't memorizing the JSON syntax.

The key idea is:

`Policy → Defines permissions`

### **Why Do We Need Users and Groups?**

The purpose is to give people access to AWS in a controlled and manageable way.

Instead of giving everyone complete access to everything, we can organize users and assign appropriate permissions.

For example:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/aad53086-01a7-4ab6-aaf4-c0f404708bb0.png align="left")

This makes access management easier as the organization grows.

### **Least Privilege Principle 🎯**

One of the most important concepts in IAM is the Least Privilege Principle.

The idea is simple:

`Give a user only the permissions they actually need.`

For example, if someone only needs access to three AWS services, don't give them permission to use every AWS service.

Instead:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/c867cfdb-e8c4-4f9a-b5fa-c3da8d65dfe9.png align="left")

rather than:

![](https://cdn.hashnode.com/uploads/covers/63f6735a437bc8d091bd105d/867aaa9b-6700-41bf-8b81-bfab0acddcad.png align="left")

Following least privilege helps improve security and can also help prevent unnecessary costs.

### **Users + Groups + Policies**

We can put everything together like this:

```plaintext
            IAM
             │
    ┌────────┴────────┐
    ↓                 ↓
  Users             Groups
    │                 │
    │          ┌──────┴──────┐
    │          ↓             ↓
    │      Developers    Operations
    │
    └───────────┐
                ↓
             Policies
                ↓
           Permissions
```

The important relationship to remember is:

`Users are individuals → Groups organize users → Policies define permissions.`

### **Key Takeaways 🔐 IAM**

`Identity and Access Management`

🔹👤 Users

Represent individual people.

🔹👥 Groups

Organize users who need similar permissions.

🔹📜 Policies

JSON documents that define permissions.

🔹🎯 Least Privilege

Give users only the access they need.

🔹🌎 Global Service

IAM is a global AWS service.

🔹👑 Root User

Created automatically with the AWS account and should be protected and avoided for everyday use.

### **Final Summary**

If you're just starting with AWS IAM, remember this simple flow:

`Create Users → Organize Users into Groups → Attach Policies → Give Required Permissions`

And always keep the Least Privilege Principle in mind.

Next topic → IAM Policies 📜🔐

#aws #IAM #cloud #devops #learning #community
