An IAM User is an AWS identity with long-term credentials - a username/password for console access and/or access keys for programmatic access.
A long-term credential pair (access key ID + secret access key) used to authenticate programmatic requests to AWS. Should be replaced with IAM roles wherever possible.
An AWS identity with temporary credentials that can be assumed by users, services, or applications to perform actions without long-term access keys.
The recommended AWS service for managing workforce access to multiple AWS accounts and applications with SSO, replacing the need for IAM users.
A security mechanism requiring two or more forms of verification (password + device/token) before granting access to an AWS account or resource.
Short-lived AWS credentials (access key, secret key, session token) issued by STS that expire automatically, eliminating the risk of permanent credential exposure.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.