AWS Identity and Access Management
Using IAM (API Version 2010-05-08)
« Previous
View the PDF for this guide.Go to the AWS Discussion Forum for this product.Go to the Kindle Store to download this guide in Kindle format.Did this page help you?  Yes | No |  Tell us about it...

Document History

This Document History is associated with the 2010-05-08 release of AWS Identity and Access Management. This guide was last updated on 3 April 2013.

The following table describes important changes since the last release of Using AWS Identity and Access Management.

ChangeDescriptionRelease Date

Policy Variables, Updated Documentation

This release adds support for including variables in policies; this makes it easier to create policies that apply to the current request context, such as to the current user. For details, see Policy Variables.

The documentation was also reorganized to make it easier to find information (for example, the table of contents was restructured), and examples were added to Example IAM Policies.

This release

Best Practices

This release includes a topic on IAM best practices. For details, see IAM Best Practices.

January 10, 2013

Cross-account API access

This release adds support for cross-account API access with IAM roles. With IAM roles, you can delegate access to resources in your AWS account so that IAM users from another AWS account can access your resources. For details, see Enabling Cross-Account API Access.

November 19, 2012

MFA-Protected API Access

This release introduces MFA-protected API access, a feature that enables you to add an extra layer of security over AWS APIs using AWS Multi-Factor Authentication (MFA), see Configuring MFA-Protected API Access.

July 8, 2012

Business Use Cases

This section has been rewritten and updated. For more information, see Business Use Cases

June 22, 2012

IAM Roles for Amazon EC2 Instances

This release introduces IAM roles for Amazon EC2 instances. Use roles to enable applications running on your Amazon EC2 instances to securely access your AWS resources. For more information about IAM roles for EC2 instances, see Roles.

June 07, 2012

AWS Storage Gateway

This release introduces AWS Storage Gateway integration with IAM. For more information about using IAM with AWS Storage Gateway, go to Access Control Using AWS Identity and Access Management (IAM) in the AWS Storage Gateway User Guide. For a general description of AWS Storage Gateway, go to AWS Storage Gateway.

May 14, 2012

Updated Documentation

The IAM Getting Started Guide was merged into Using IAM, and Using IAM was reorganized to enhance usability. The Getting Started is now available at Getting Started.

May 02, 2012

Signature Version 4

With this release of IAM, you can use Signature Version 4 to sign your IAM API requests. For more information about Signature Version 4, go to Signature Version 4 Signing Process in the AWS General Reference.

March 15, 2012

User Password Management

With this release of IAM, you can enable your IAM users to change their password. For more information, see Managing Passwords.

March 08, 2012

Account Password Policy

IAM now includes an account-wide password policy you can use to ensure your IAM users create strong passwords. For more information, see Managing an IAM Password Policy.

March 08, 2012

IAM User Access to Your AWS Account Billing Information

With this release of IAM, you can enable your IAM users to access your AWS account billing and usage information. For more information, see Controlling User Access to Your AWS Account Billing Information.

March 08, 2012

Amazon Simple Workflow Service (SWF)

This release introduces Amazon Simple Workflow Service (SWF) integration with IAM. For more information about using IAM with Amazon Simple Workflow Service, go to Managing Access to Your Amazon SWF Workflows in the Amazon Simple Workflow Service Developer Guide . For a general description of Amazon Simple Workflow Service, go to Amazon Simple Workflow Service.

February 22, 2012

Single Sign-on Access to the AWS Management Console for Federated Users

With this release, you can give your federated users single sign-on access to the AWS Management Console through your identity and authorization system, without requiring users to sign in to Amazon Web Services (AWS). For more information, go to Giving Federated Users Direct Access to the AWS Management Console in Using Temporary Security Credentials.

January 19, 2012

New Documentation: Using Temporary Security Credentials

The documentation that describes creating temporary security credentials for federated users and mobile applications has been moved to a new, expanded stand-alone guide named Using Temporary Security Credentials.

January 19, 2012

Amazon DynamoDB

This release introduces Amazon DynamoDB integration with IAM. For more information about using IAM with Amazon DynamoDB, go to Controlling Access to Amazon DynamoDB Resources in the Amazon DynamoDB Developer Guide. For a general description of Amazon DynamoDB, go to Amazon DynamoDB.

January 18, 2012

AWS Elastic Beanstalk

This release introduces AWS Elastic Beanstalk integration with IAM. For more information about using IAM with AWS Elastic Beanstalk, go to Using AWS Elastic Beanstalk with AWS Identity and Access Management (IAM) in the AWS Elastic Beanstalk Developer Guide. For a general description of AWS Elastic Beanstalk, go to AWS Elastic Beanstalk. For IAM use cases, see Business Use Cases.

November 21, 2011

AWS Virtual MFA

With this release, you can use IAM to configure and enable a virtual MFA device. A virtual MFA device uses a software application that can generate six-digit authentication codes that are compatible with the Time-Based One-Time Password (TOTP) standard, as described in RFC 6238. The software application can run on any mobile hardware device, including a smartphone. For more information about virtual MFA and about using IAM to configure and enable a virtual MFA device, see Using a Virtual MFA Device with AWS.

November 02, 2011

Policy Generator Integration with the AWS Identity and Access Management Console

This release introduces the integration of the policy generator with the AWS Identity and Access Management (IAM) console. Integrating the policy generator with the IAM console makes it even easier to set permissions for your IAM users and groups. To use the policy generator in the console, select Policy Generator in the user or group permissions dialogs.

For more information about the AWS access policy language, see Overview of Policies in Using AWS Identity and Access Management. If you want to use the policy generator online to create policies for AWS products without accessing the console, go to the AWS Policy Generator.

October 06, 2011

Amazon ElastiCache

This release introduces Amazon ElastiCache integration with IAM. For more information about using IAM with ElastiCache, go to Controlling User Access to Your AWS Account in the Amazon ElastiCache User Guide. For a general description of Amazon ElastiCache, go to Amazon ElastiCache. For IAM use cases, see Business Use Cases.

August 22, 2011

Temporary Security Credentials

This release of IAM introduces temporary security credentials that you can use to grant temporary access to non-AWS users (federated users), to IAM users who need temporary access to your AWS resources, and to your mobile and browser-based applications that need to access your AWS resources securely. For more information, go to Using Temporary Security Credentials.

August 03, 2011

Cross-Account Access for IAM Users

This release of IAM introduces cross-account access for IAM users. For more information, see Roles.

June 06, 2011

The AWS Management Console IAM Tab

This release of IAM introduces AWS Management Console support. The IAM tab of the console is a graphical user interface (GUI) that enables you to do almost everything you can do with the IAM APIs. For more information, see Accessing IAM.

May 03, 2011

Amazon CloudFront

This release of IAM includes integration with Amazon CloudFront. For more information, go to Controlling User Access to Your AWS Account in the Amazon CloudFront Developer Guide.

March 10, 2011

AWS CloudFormation

This release introduces AWS CloudFormation integration with IAM. For more information, go to Controlling User Access With AWS Identity and Access Management in the Amazon CloudFront Developer Guide.

24 February 2011

Amazon Elastic MapReduce

This release introduces Amazon Elastic MapReduce integration with IAM. For more information, go to Amazon Elastic MapReduce in Business Use Cases in Using AWS Identity and Access Management.

22 February 2011

IAM-Enabled User Access to the AWS Management Console and AWS Developer Forums

IAM now provides an IAM-enabled sign-in page for the AWS Management Console. You provide your users with a login profile and with appropriate permissions so they can access your available AWS resources through the AWS Management Console. For information about accessing the AWS Management Console through IAM, see IAM and the AWS Management Console. For information about the AWS Management Console, see AWS Management Console.

14 February 2011

Amazon Simple Email Service

This release introduces Amazon Simple Email Service (Amazon SES) integration with IAM. For more information, see Controlling User Access with IAM.

24 January 2011

AWS IAM Integration with Amazon Route 53

Amazon Route 53 DNS service is now integrated with IAM. For information about using Amazon Route 53 with IAM, see AWS Services that Support IAM. For more information about Amazon Route 53, go to Amazon Route 53 on the AWS website.

05 December 2010

AWS IAM Integration with Amazon CloudWatch

Amazon CloudWatch is now integrated with IAM. For information about using Amazon CloudWatch with IAM, see Controlling User Access to Your AWS Account. For more information about Amazon CloudWatch, see Amazon CloudWatch on the AWS website.

29 November 2010

Server Certificate Support

IAM now provides server certificate APIs for use with Elastic Load Balancing server certificates. For information about using IAM to manage server certificates, see Managing Server Certificates.

14 October 2010

Initial Release

This is the first release of Using AWS Identity and Access Management.

02 September 2010