Create IAM Limited User
Create IAM Limited User
After creating a policy that limits maximum permissions, we will create an IAM user and apply a permission limit to that user.
- Login to IAM Management Console
data:image/s3,"s3://crabby-images/41755/4175583908fd0f8faad0c31dde4556ec3d9ce6ca" alt="IAM User"
- In the left sidebar select Users and then select Add user.
3. On the Set user details page, enter the following parameters and then select Next Permissions:
- User name: ec2-admin.
- Access type: Select AWS Management Console access to allow users to login to AWS Management Console.
- Select Custom Password and set a password of your choice.
- Uncheck “User must create a new password at next sign-in”.
data:image/s3,"s3://crabby-images/36355/363554ed7741e83f47c4804114960d8cbf4972be" alt="IAM USer"
4 In the Set permissions section, you need to do the following:
- Select Attach existing policies directly to assign policy directly to IAM user.
- Find and tick AmazonEC2FullAccess to assign EC2 admin rights to IAM user.
data:image/s3,"s3://crabby-images/df0df/df0df6d0afcf0774a384640a0967c5e625d3023f" alt="IAM USer"
-
Then expand the Set permissions boundary section and:
- Select Use a permissions boundary to control the maximum user permissions
- In the Search box, type “ec2-admin-restrict-region” to find and select the restriction policy we created.
- Check and select Next: Tags
data:image/s3,"s3://crabby-images/6cabe/6cabe1f9980b2beced0ddf5f76949f2340a95841" alt="IAM USer"
- On the Add tags (optional) page, keep the defaults and select Next-Review.
data:image/s3,"s3://crabby-images/aab83/aab830b4b3de53aeba2d28c44b0bbcc84c955026" alt="IAM USer"
- On the Review page, double-check and select Create user.
data:image/s3,"s3://crabby-images/3be5f/3be5ffcfda36e92b98f5ca3b842aa3c52c15e3ff" alt="IAM USer"
- Thus, the user has been created successfully, in the next step we will log in with the newly created ec2-admin user to check if that user can create EC2 instances in the Region different from the Region we have limited or not.
data:image/s3,"s3://crabby-images/dc110/dc1103f074017994ace22adcf526997dedac6dd4" alt="IAM USer"
- We will use this IAM user for the next step.
data:image/s3,"s3://crabby-images/4a974/4a97414d50337dd2a38e6f5ae0e0ff3167ada382" alt="IAM USer"