IT & Cloud free courses

Master the TrickFoundationFree

Cloud IAM and Least Privilege

Plan scoped access for people and services, including temporary credentials and permission reviews.

3 reading lessons · about 30 min ·written by MTT

The idea

Authentication establishes an identity; authorization evaluates its allowed actions. People and workloads can have different identity mechanisms. Avoid shared accounts that obscure accountability, and use appropriate multifactor protection for people. An authenticated identity is not automatically entitled to every resource.

Worked example

A fictional analyst signs in successfully but can only read the reporting bucket. A background import service uses its own workload identity. Sharing an administrator account between both would grant excessive authority and make their actions harder to distinguish.

Try it

List two people and one fictional service with their tasks. Assign separate identities and define what successful sign-in does and does not permit. Identify an administrative action none of these daily tasks needs.

Lesson 1 of 3 · About 10 min

Identify who is acting

Check your understanding

Course quiz

Finish the course to unlock the quiz

Complete all 3 lessons and 5 questions open up here. You have 3 to go.

What you will learn

  • Separate authentication from authorization
  • Scope actions to required resources
  • Review and revoke unnecessary access

Before you start

Prerequisites
None. Exercises use fictional policies and require no live cloud account.
Cost
Free introductory reading lessons, exercises and quiz. Optional third-party tools, hosting or AI subscriptions may cost money.

Original introductory lessons and assessment by Master the Trick. Estimated times include the suggested exercises.