Module 09 of 15

Identity & Security

Lessons

About This Module

In the Cloud Networking module you built the private network your resources live in. Now you'll decide who and what is allowed to use them. In the cloud, almost everything is controlled through identity: every person, application and service that touches your account has to prove who it is and is only allowed to do what its permissions say. The core service is identity and access management (IAM), built from users, groups, roles and policies.

You'll then strengthen sign-in with multi-factor authentication (MFA) and single sign-on (SSO), protect data with encryption keys in a key management service, and keep passwords and API keys out of your code with secrets management. Throughout, you'll apply the principle of least privilege: give each identity only the access it needs. The examples use AWS, but Azure and Google Cloud offer the same ideas under different names. Watch the videos in order, then move on to Infrastructure as Code.

Lessons

5 videos
01

Identity & Access Management: The Core Concepts

A high-level overview of IAM and how users, groups, roles and policies fit together.

02

Hands-On IAM: Users, Groups, Roles, Policies & MFA

Create and manage IAM identities in the console, attach policies, and turn on multi-factor authentication.

03

Single Sign-On with IAM Identity Center

How to give people one central login across your AWS accounts and applications.

04

Encrypting Data with AWS KMS

How the Key Management Service creates, stores and controls the encryption keys that protect your data.

05

Managing Secrets with AWS Secrets Manager

Store, rotate and delete credentials and API keys safely instead of hardcoding them.