Let’s Create an IAM Group
An IAM group is a collection of users. Groups are often based on job function and can be used to simplify provisioning common user access requirements. They allow you to manage permissions by applying policies to groups of users, rather than applying policies to each individual user.
1- Access the AWS IAM console and select Groups from the sidebar or go to
https://console.aws.amazon.com/iam/home?region=us-east-1#/groups. Click Create New Group.
2 -Type in Contractors as the Group Name. Go to the Next Step.
3- On the Attach Policy screen, enter the search string “S3” in the search bar and check the
the checkbox next to the AWS managed policy titled “AmazonS3ReadOnlyAccess”.
4- On the same Attach Policy screen execute a second search. Enter the search string “contractors” for a and add the customer-managed policy named “Contractorspolicy”. Policies
are what give IAM entities permissions. AWS provides managed policies for many common
access needs. We will use the AmazonS3ReadOnlyAccess which will provide read-only access to the Amazon Simple Storage Service (S3) to all members of the Contractors group. Click Next Step.
5 – On the review screen, click Create Group.
6- The group is created, and you are returned to the Group creation IAM console. Select the
Contractors group and chose “Add Users to Group” from the Group Actions Menu Dropdown.
7- Add the user’s named John and Bob to the Contractors group. Check the checkbox next to their names and click “Add Users”. The IAM groups dashboard will now show the Contractors group
has 2 users.
Congratulations! You have created an IAM Group and attached the AWS managed policy AmazonS3ReadOnlyAccess which provides read only access to Amazon Simple Storage Service (S3) to members of this group. You added the customer managed policy named “contractorsroleassumptionpolicy” which will allow members of this group to assume roles which have been tagged with a Key of contractorsassumerole and a Value of true. You added the IAM users John and Bob into the Contractors group.
This post was created with our nice and easy submission form. Create your post!