View a markdown version of this page

Authenticating with identities - AWS End User Messaging

Authenticating with identities

Authentication is how you sign in to AWS using your identity credentials. You must be authenticated (signed in to AWS) as the AWS account root user, as an IAM user, or by assuming an IAM role.

You can sign in to AWS as a federated identity by using credentials provided through an identity source. AWS IAM Identity Center (IAM Identity Center) users, the single sign-on authentication of your company, and your Google or Facebook credentials are examples of federated identities. When you sign in as a federated identity, your administrator previously set up identity federation using IAM roles. When you access AWS by using federation, you are indirectly assuming a role. For more information about signing in, see How to sign in to your AWS account in the AWS Sign-In User Guide.

For programmatic access, AWS provides a software development kit (SDK) and a command line interface (CLI) to cryptographically sign requests by using your credentials. For more information, see AWS Signature Version 4 for API requests in the IAM User Guide.

AWS account root user. When you create an AWS account, you begin with one sign-in identity that has complete access to all AWS services and resources in the account. This identity is called the AWS account root user. We strongly recommend that you do not use the root user for your everyday tasks. For tasks that require root user credentials, see Tasks that require root user credentials in the IAM User Guide.

Federated identity. As a best practice, require human users, including users that require administrator access, to use federation with an identity provider to access AWS services by using temporary credentials. A federated identity is a user from your enterprise user directory, a web identity provider, AWS IAM Identity Center, or any user that accesses AWS services by using credentials provided through an identity source. When federated identities access AWS accounts, they assume roles, and the roles provide temporary credentials. For centralized access management, we recommend that you use AWS IAM Identity Center. For more information, see What is IAM Identity Center? in the AWS IAM Identity Center User Guide.

IAM users and groups. An IAM user is an identity within your AWS account that has specific permissions for a single person or application. Where possible, we recommend relying on temporary credentials instead of creating IAM users that have long-term credentials such as passwords and access keys. An IAM group is an identity that specifies a collection of IAM users. You cannot sign in as a group. You can use groups to specify permissions for multiple users at a time. For more information, see Use cases for IAM users in the IAM User Guide.

IAM roles. An IAM role is an identity within your AWS account that has specific permissions. It is similar to an IAM user, but is not associated with a specific person. IAM roles are useful for federated user access, temporary IAM user permissions, cross-account access, cross-service access, and applications that run on Amazon EC2. For more information, see Methods to assume a role in the IAM User Guide.