We have updated this course on December 5, 2022 to correct a problem that was impacting course completion. If you are enrolled in the course and have not completed it, your progress may be impacted. We apologize for any inconvenience this may cause.
    ÂAs you build and deploy on AWS, granting developers and applications the right access to the right resources is critical to security. This self-paced course provides a deep dive into AWS Identity and Access Management (IAM) and best practices for using IAM policies. This course also covers advanced concepts, such as identity federation, temporary credentials, AWS IAM Identity Center, and ways to troubleshoot access issues.  Â
- Course level: IntermediateÂ
- Duration:Â 8Â hoursÂ
ActivitiesÂ
This course includes interactive content, videos, assessments, and exercises.Â
Course objectivesÂ
In this course, you will learn to:Â
- Use and differentiate between role-based and attribute-based access controls    Â
- Leverage global and IAM condition keys according to best practices   Â
- Interact with AWS Security Token Service (AWS STS) for temporary credentials   Â
- Manage IAM session policies and duration to scope down permissions   Â
- Create an IAM identity provider   Â
- Demonstrate how you can use AWS IAM Identity Center in identity federation   Â
- Troubleshoot IAM access issuesÂ
Intended audienceÂ
This course is intended for:Â
- Security professionals with working knowledge of AWS     Â
- Users with an AWS account looking to build their knowledge on how best to use IAMÂ
PrerequisitesÂ
We recommend that attendees of this course have:Â
- Have 1-2 years of experience using IAM to manage access via policies and roles  Â
- Have taken the AWS Security Fundamentals (2nd Edition) digital training or attended the AWS Security Essentials classroom trainingÂ
Course outlineÂ
Module 1: AWS Identity and Access Management Review Â
- IAM FundamentalsÂ
- IAM Policy BasicsÂ
- Policy Evaluation OverviewÂ
Module 2: Access Control Deep Dive    Â
- The Matching Game     Â
- Attributes and Tagging   Â
- IAM Condition Keys   Â
- Global Condition Keys    Â
- Advanced Policy Elements   Â
Module 3: Access Delegation Deep Dive     Â
- Interacting with AWS STS    Â
- Managing Role Sessions     Â
- Session Tagging    Â
Module 4: Identity Federation Deep Dive    Â
- Federating Users in AWS     Â
- SAML-Based Federation   Â
- Web-Based Federation    Â
- AWS IAM Identity Center for User FederationÂ
Module 5: Access Analysis and Troubleshooting    Â
- IAM Policy Simulator     Â
- IAM Access Analyzer   Â
- Viewing Access History     Â
- Troubleshooting with AWS CloudTrail