What it is

IAM is the permission system for AWS. Users, groups, roles, and policies decide who can create, read, delete, or bill. Without it, the account is a shared laptop with root stickers everywhere.

Roles are how workloads get permission without long-lived keys on a laptop. Policies are the actual rules. AdministratorAccess is the big red button people reach for when the right policy would take twenty minutes.

Azure Entra ID plus Azure RBAC cover the same ground on the other cloud. Different nouns. Same fight between speed and blast radius.

Why it matters in the meeting

Every scary cloud story has an identity chapter. A key with too much power. A user who left. A role that still has admin "temporarily." Bart asks about IAM before he asks about firewalls.

JJ wants the report today. Selena pastes admin credentials into Slack at 7:43am. The dashboard works. So do three other things JJ was never supposed to reach.

Real world

Least privilege, MFA, and short-lived roles are boring. They are also how you sleep. Access keys in GitHub are exciting for the wrong people.

If you cannot list who has admin and why, you do not have an identity strategy. You have folklore.

In plain terms

IAM is the lockboard for the account. Admin for convenience is how convenience becomes an incident. Grant the job, not the kingdom.

What to ask

  • Who has AdministratorAccess right now, named, not "a few people"?
  • Do apps use roles, or long-lived access keys?
  • Is MFA required for humans who can change production?
  • When was the last access review, and who signed it?

You just knew a little more Jack than you did five minutes ago.

All concepts