Bobcares

IAM assign Role to User – Assign it with ease

by | Aug 29, 2020

In IAM, you can assign an IAM role to an IAM user, wondering how to do it? Then take a peek at this blog.

Here at Bobcares, we have seen several such AWS related queries as part of our AWS Support Services for AWS users, and online service providers.

Today we’ll take a look at how to assign IAM users to the IAM role.

 

Know more about IAM user

An AWS user is an entity that is created to represent a person or an application that uses to interact with AWS.

A user in AWS comprises of username and credentials. An IAM user with administrator permissions is not the same thing as the AWS account root user.

 

How does an IAM user sign in?

In order to sign in to AWS Management Console as an IAM user, you need an account ID, username, and password.

When we create an IAM user in the console, we will be provided with the username and the account sign-in page URL. This URL includes the account ID as below

https://My_AWS_Account_ID.signin.aws.amazon.com/console/

However, you can also sign into the account using the below general URL and enter the account ID manually.

https://console.aws.amazon.com/

For user convenience, the AWS sign-in page uses a browser cookie so that it remembers the IAM username and account details. As a result, when the user accesses any page in AWS Management Console, the console uses the cookie to redirect the user to the account sign-in page.

 

Know more about IAM Role

An IAM is an IAM entity that defines a set of permissions that grant access to actions and resources in AWS.

It is not associated uniquely to a specific user or group. Instead, trusted entities assume roles, such as IAM users, applications, or AWS services such as EC2.

 

In IAM, how we assign a role to a user?

Now let’s see what instructions our Support Engineers provide to assign IAM users to an IAM role.

In order to assign an existing IAM role to an AWS Directory Service user or group, the role must have a trust relationship with AWS Directory Service.

Here are the steps below to assign users or groups to an IAM role.

1. First, access the AWS Directory Service console navigation pane, here choose Directories.

2. On the Directories page, choose your directory ID. Then in the Directory details page, select the Application management tab.

3. In the AWS Management Console section, under Delegate console access, choose the IAM role name for the existing IAM role that you want to assign users to. If the role has not yet been created, then create a New Role.

4. On the Selected role page, under Manage users and groups for this role, choose Add.

5. On the Add users and groups to the role page, under Select Active Directory Forest, choose either the AWS Managed Microsoft AD forest (this forest) or the on-premises forest (trusted forest), whichever contains were the accounts that need access to the AWS Management Console.

6. After that, under Specify which users or groups to add, select either ‘Find by user‘ or ‘Find by group‘. Then type the name of the user or group. In the list of possible matches, choose the user or group that you want to add.

7. Finally, choose Add to finish assigning the users and groups to the role.

You can’t access users in nested groups within your directory as it is not supported. Because members of the parent group have console access, but members of child groups do not.

[Need any further assistance in assigning IAM roles to users? – We are here to help you.]

 

Conclusion

Today, we saw how to assign an existing IAM Role to an IAM user.

Get 24x7 monitoring for your AWS servers

There are proven ways to get even more out of your AWS Infrastructure! Let us help you.

Spend your time in growing business and we will take care of AWS Infrastructure for you.

GET STARTED

var google_conversion_label = "owonCMyG5nEQ0aD71QM";

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Never again lose customers to poor
server speed! Let us help you.

Privacy Preference Center

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

PHPSESSID - Preserves user session state across page requests.

gdpr[consent_types] - Used to store user consents.

gdpr[allowed_cookies] - Used to store user allowed cookies.

PHPSESSID, gdpr[consent_types], gdpr[allowed_cookies]
PHPSESSID
WHMCSpKDlPzh2chML

Statistics

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

_ga - Preserves user session state across page requests.

_gat - Used by Google Analytics to throttle request rate

_gid - Registers a unique ID that is used to generate statistical data on how you use the website.

smartlookCookie - Used to collect user device and location information of the site visitors to improve the websites User Experience.

_ga, _gat, _gid
_ga, _gat, _gid
smartlookCookie
_clck, _clsk, CLID, ANONCHK, MR, MUID, SM

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

IDE - Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.

test_cookie - Used to check if the user's browser supports cookies.

1P_JAR - Google cookie. These cookies are used to collect website statistics and track conversion rates.

NID - Registers a unique ID that identifies a returning user's device. The ID is used for serving ads that are most relevant to the user.

DV - Google ad personalisation

_reb2bgeo - The visitor's geographical location

_reb2bloaded - Whether or not the script loaded for the visitor

_reb2bref - The referring URL for the visit

_reb2bsessionID - The visitor's RB2B session ID

_reb2buid - The visitor's RB2B user ID

IDE, test_cookie, 1P_JAR, NID, DV, NID
IDE, test_cookie
1P_JAR, NID, DV
NID
hblid
_reb2bgeo, _reb2bloaded, _reb2bref, _reb2bsessionID, _reb2buid

Security

These are essential site cookies, used by the google reCAPTCHA. These cookies use an unique identifier to verify if a visitor is human or a bot.

SID, APISID, HSID, NID, PREF
SID, APISID, HSID, NID, PREF