Prev Question
Next Question

An organization has launched 5 instances: 2 for production and 3 for testing. The organization
wants that one particular group of IAM users should only access the test instances and not the
production ones. How can the organization set that as a part of the policy?

Launch the test and production instances in separate regions and allow region wise access to

Define the IAM policy which allows access based on the instance ID

Create an IAM policy with a condition which allows access to only small instances

Define the tags on the test and production servers and add a condition to the IAM policy which
access to specific tags

AWS Identity and Access Management is a web service which allows organizations to manage
users and user permissions for various AWS services. The user can add conditions as a part of
the IAM policies. The condition can be set on AWS Tags, Time, and Client IP as well as on various
parameters. If the organization wants the user to access only specific instances he should define
proper tags and add to the IAM policy condition. The sample policy is shown below.
“Statement”: [
“Action”: “ec2:*”,
“Effect”: “Allow”,
“Resource”: “*”,
“Condition”: {
“StringEquals”: {
“ec2:ResourceTag/InstanceType”: “Production”

Prev Question
Next Question

Leave a Reply

Your email address will not be published. Required fields are marked *