SIVA 99

Amazon Identity and Access Management (IAM) Tasks

1. AWS Account creation

It open below Screen Shot Page, In Root user email address, enter your email address & In the AWS account name, enter what name you need, and then choose Verify email address.

Now, open below Screen shot, check your email and spam folder for the verification code email. then enter OTP & Verify email address

Now, open below Screen shot, Enter your Root user password and Confirm root user password, and then choose Continue.

Now, open below Screen shot, add your contact information
Select Personal or Business.
Note: Personal accounts and business accounts have the same features and functions.
Enter your contact information and then choose Continue.

Now, open below Screen shot, Add a payment methods & and then choose Verify and Add.

Now, open below Screen shot, Verify your phone number and then choose Send SMS

Now, open below Screen shot, enter OTP and then choose Continue.

Now, open below Screen shot, Choose an AWS Support plan and then choose complete sign up

Now, open below Screen shot, Choose an My Role & i am interested and then submit.

After Submission, open login Page... using the mail id & Password You can looged in & use AWS Services...

2. Enable MFA for root account

Once You logged into AWS account, top menu right side click on account name open below screen shot like this...

After Clicking Security Credentials, open below screen shot

After Clicking the Activate MFA, open below screen shot

After Clicking the Continue Button, open below screen shot Screen, Now You can download "Google Authenticator" from Your Playstore. after download you can click on show QR code, point your phone camera to the QR code. This will add the account into Google Authenticator. You will start to see 6 digit codes appear and change every 30 seconds.

Enter 2 consecutive codes into ‘MFA code 1’ and ‘MFA code 2’ fields and click on Assign MFA.

Your Multifactor authentication on your root aws account is now complete and ready to use.

The next time you log into your AWS console, you will be prompted to enter an MFA code.

Go back into your Google Authenticator App on your phone, and type in the 6 digits that appear.

4. Create IAM user and give give only s3 & Ec2 access

Once You logged into AWS account, go to IAM Service. then choose Users & select add users

After Selecting Add Users it going to below screen shot screen. Give Username, select access type , Give Password & if you give once login user password reset you can enable that option. once done these operations click the permissions.

After Selecting the Permissions button it going to below screen shot screen. you can give permissions what you need. & then choose tags.

After Selecting the tags button it going to below screen shot screen. you can give tags & then choose review.

After Selecting the review button it going to below screen shot screen. you can check what values you have given before steps. then ok you can create the user.

After Selecting the Create User button it going to below screen shot screen. you can give the URL for user & Download file. you want to do this things mailed too.

4. Create IAM user and give only s3 & Ec2 access

Once You logged into AWS account, go to IAM Service. then choose Users & select add users

After Selecting Add Users it going to below screen shot screen. Give Username, select access type , Give Password & if you give once login user password reset you can enable that option. once done these operations click the permissions.

After Selecting the Permissions button it going to below screen shot screen. you can give permissions what you need. & then choose tags.

After Selecting the tags button it going to below screen shot screen. you can give tags & then choose review.

After Selecting the review button it going to below screen shot screen. you can check what values you have given before steps. then ok you can create the user.

After Selecting the Create User button it going to below screen shot screen. you can give the URL for user & Download file. you want to do this things mailed too.