Definition: A collection of IAM users. Policies can be attached to groups to manage permissions for multiple users simultaneously.
Characteristics
Non-Principal: A group itself is not an identity and cannot be identified as a principal in an IAM policy.
Permission Management: Groups are used to assign permissions to users collectively, simplifying management.
Best Practices
Least Privilege: Apply the principle of least privilege when assigning permissions to groups. Only grant permissions that are necessary for the group's function.
No Nesting: Groups cannot be nested (i.e., you cannot create groups within groups).
Want to print your doc? This is not the way.
Try clicking the ⋯ next to your doc name or using a keyboard shortcut (