[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"next-aws-certified-cloudops-engineer-associate-security-and-compliance-iam-and-access-management-mfa-federation-and-account-security-en":4,"lesson-aws-certified-cloudops-engineer-associate-security-and-compliance-iam-and-access-management-mfa-federation-and-account-security-en":20,"prev-aws-certified-cloudops-engineer-associate-security-and-compliance-iam-and-access-management-mfa-federation-and-account-security-en":32},null,{"locked":5,"reason":6,"meta":7,"item":3},true,"paywall",{"title":8,"description":9,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":13},"Troubleshooting Access with IAM Tools","Turning an AccessDenied into an answer: reading what the error message already tells you, testing with the policy simulator, and using IAM Access Analyzer, last accessed information, the credential report, and CloudTrail to find both the permissions you are missing and the ones you should never have granted.",false,25,"intermediate",[14,15,16,17,18,19],"Read an AccessDenied message and name the policy type that produced it","Distinguish an implicit deny from an explicit deny by the wording of the error alone","Run the policy simulator and state which policy types it does and does not evaluate","Select the right IAM Access Analyzer analyzer type for external, internal, and unused access questions","Interpret last accessed information within its tracking periods and excluded policy types","Order the diagnostic steps so the cause of a denied request is found with the least work",{"locked":5,"reason":6,"meta":21,"item":3},{"title":22,"description":23,"isFree":10,"estimatedMinutes":24,"difficulty":12,"learningObjectives":25},"MFA, Federation, and Account Security","Hardening the credentials themselves: the root user and the tasks that still require it, password policy limits, the MFA types AWS supports and how to enforce them, access key hygiene, and the federation options that let you stop creating IAM users at all.",24,[26,27,28,29,30,31],"Identify the tasks that require AWS account root user credentials and the controls that protect it","Configure an account password policy within the ranges AWS allows and predict which settings apply immediately","Compare the 3 MFA types AWS supports and choose the phishing-resistant option","Enforce MFA on sensitive actions and explain which STS operations can carry MFA information","Decide when an IAM user with long-term access keys is still the right answer","Choose between IAM Identity Center, SAML or OIDC federation in IAM, and Amazon Cognito for a given set of users",{"locked":5,"reason":6,"meta":33,"item":3},{"title":34,"description":35,"isFree":10,"estimatedMinutes":36,"difficulty":37,"learningObjectives":38},"Policy Evaluation and Conditions","How AWS turns 6 competing policies into one allow or deny: the enforcement order, which policy types add permissions and which only subtract, permissions boundaries, and the condition operators and global condition keys that decide the close calls.",30,"advanced",[39,40,41,42,43,44],"State the AWS enforcement order and name what happens at each gate","Predict whether a given pair of policy types combines as a union or an intersection","Explain why a permissions boundary can deny a request that an identity-based policy allows","Choose the correct condition operator for a key, including the IfExists and Null forms","Apply the rule that a missing condition key makes an ordinary condition false, and describe where that rule inverts","Select the right global condition key for network, organization, MFA, and tagging restrictions"]