IAM Basics — Complete Guide
IAM Basics — Complete Guide: free step-by-step lesson with examples, common mistakes, and interview tips — part of AWS Cloud Tutorial on Toolliyo Academy.
On this page
AWS Cloud Tutorial · Lesson 6 of 100
IAM Basics
Core services → Projects
Core services · 1 — AWS basics · ~6 min · AWS — Foundations
What is this?
IAM controls who can access AWS and what they can do. Users, groups, roles, and policies attach permissions using least privilege.
Why should you care?
AwsVerse banking workloads require role-based access so tellers, ops, and CI pipelines each get only what they need.
See it live — copy this example
Run in AWS CloudShell / local AWS CLI v2, or follow the matching steps in the AWS Console (Free Tier).
aws iam create-policy \
--policy-name AwsVerseS3ReadAudit \
--policy-document '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:GetObject","s3:ListBucket"],"Resource":["arn:aws:s3:::awsverse-audit/*","arn:aws:s3:::awsverse-audit"]}]}'
What happened?
- Creates a custom policy granting read-only access to one audit bucket.
- Attach it to a group or role — never embed keys in code.
Practice next
- Create IAM group Developers with PowerUserAccess (lab) or custom policy.
- Create user with console password + MFA.
- Attach policy; test with aws s3 ls under that profile.
- Add a Deny statement for s3:DeleteObject on the audit bucket.
- Create a role EC2-S3Read and attach the policy.
Remember
Policies define Allow/Deny on actions. Roles for EC2, Lambda, and CI. Least privilege always.
AwsVerse teller role
Branch staff must view statements, not delete buckets.
Outcome: Read-only S3 policy on a group cuts audit findings.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!