1
00:00:00,720 --> 00:00:06,150
In this video, we are going to talk about security, best practices of 8 seconds.

2
00:00:06,720 --> 00:00:11,280
We will see the way of improving the security of your account.

3
00:00:11,610 --> 00:00:18,600
As you know that in the last video we have activated our Willis filter account and log into a management

4
00:00:18,600 --> 00:00:19,260
console.

5
00:00:20,380 --> 00:00:27,340
So Ada has two main user type one log in the A management console you can see in this picture.

6
00:00:27,340 --> 00:00:35,290
Also the first one is the A list root user account and the second one is the A Willis Iam user account.

7
00:00:35,970 --> 00:00:39,780
I am stands for the Identity and Access Management.

8
00:00:40,020 --> 00:00:45,630
And as the name suggests, it is managing identity and access of the resources.

9
00:00:46,710 --> 00:00:49,440
Look, let me explain one by one these user accounts.

10
00:00:49,470 --> 00:00:52,230
The first one is the root user account.

11
00:00:52,620 --> 00:01:00,630
As you guessed that a root user account is the only one user that has full powerful of your account

12
00:01:00,870 --> 00:01:05,970
and it has unrestricted access over your aid account.

13
00:01:06,390 --> 00:01:12,570
So that means it is really, really dangerous to use this root account for daily usage of your cloud

14
00:01:12,570 --> 00:01:19,050
infrastructure because it has powerful of everything on your aid list environment.

15
00:01:20,320 --> 00:01:23,830
So the second one is the IAM user account.

16
00:01:23,830 --> 00:01:31,600
Iam is identity and access management and you can think this is a sub user's under the root user account

17
00:01:31,600 --> 00:01:39,010
and you can define policies over this account and able to restrict over your a closed account.

18
00:01:39,010 --> 00:01:48,160
So that means I am a user account can create and restrict by a root user accounts and this is the best

19
00:01:48,160 --> 00:01:55,330
practice when you are using the alias, creating iam user and configuring for the programmatic is the

20
00:01:55,330 --> 00:01:56,200
best practice.

21
00:01:56,410 --> 00:01:58,300
Let me explain better way.

22
00:01:58,720 --> 00:02:06,610
So this is the best practice to follow when you first activate your account is you know that we have

23
00:02:06,610 --> 00:02:15,220
just activated a split account and after activate our account we have got only an A root user account,

24
00:02:15,220 --> 00:02:15,760
right?

25
00:02:15,850 --> 00:02:23,290
So this is the first thing we should do when creating IAM user on the root account and use this IAM

26
00:02:23,290 --> 00:02:26,680
user for our daily usage of a management console.

27
00:02:27,250 --> 00:02:30,970
Even you have the only one user to use this account.

28
00:02:30,970 --> 00:02:38,770
Creating a dedicated user account is one of the first thing we should do after activated our account.

29
00:02:38,800 --> 00:02:42,790
This is the best practice security, best practice that we should follow.

30
00:02:43,240 --> 00:02:51,370
So that means we should create user specific IAM accounts under the root user account that they have

31
00:02:51,370 --> 00:02:59,530
own login and password information because root contains power of full access that can change your payment

32
00:02:59,530 --> 00:03:05,440
information, changing your password, removing users and lots of dangerous things.

33
00:03:05,560 --> 00:03:12,610
So the important to security best practice is creating IAM user account under your root user account.

34
00:03:12,670 --> 00:03:18,700
So when creating user specific account, we should define programmatic and console access.

35
00:03:19,150 --> 00:03:27,160
Also, programmatic access is required for our course because we will use all interactions with a resources

36
00:03:27,160 --> 00:03:28,870
like a management console.

37
00:03:29,050 --> 00:03:36,940
A CDK and SDHC will be required to programmatic access in order to interrupt existing resources.

38
00:03:36,940 --> 00:03:42,760
So it is important to creating a new IAM user and configure for the programmatic and console access.

39
00:03:43,060 --> 00:03:50,320
So we will create a we will follow this security based practice and create an IAM user account and configure

40
00:03:50,320 --> 00:03:52,300
for the programmatic and console access.

41
00:03:52,630 --> 00:03:55,510
But let me show you how we can do that.

42
00:03:56,290 --> 00:04:00,880
If you open the signing console page, let me open it.

43
00:04:00,910 --> 00:04:04,990
Yes, you can see in here we have two options, right.

44
00:04:05,020 --> 00:04:09,810
We can log in with the root user account and log in with the user account.

45
00:04:09,820 --> 00:04:15,790
And as you said that I am stands for the identity and access management and as the name suggests, it

46
00:04:15,790 --> 00:04:18,790
is managing identity and access of resources.

47
00:04:19,540 --> 00:04:24,970
So in the next video, we are going to create our IAM user and give required permissions and login with

48
00:04:24,970 --> 00:04:28,180
the IAM user because it is a security based practice.

49
00:04:28,390 --> 00:04:34,270
But before that, I would like to share you other security best practices that you should also follow

50
00:04:34,270 --> 00:04:36,760
and consider about the accounts.

51
00:04:37,120 --> 00:04:43,660
As you know that we have followed these steps in this page, we have followed this step one, we are

52
00:04:43,690 --> 00:04:46,420
create and activate our liquidity account.

53
00:04:46,840 --> 00:04:55,030
And at the end of this page you can see the part of the yes, improving the security of the account

54
00:04:55,030 --> 00:04:58,720
and you can see the security best practices in the willis iam.

55
00:04:58,900 --> 00:05:05,650
So if you click this link you can see the lots of security best practices that we can follow.

56
00:05:06,370 --> 00:05:13,450
It is basically to help secure your account and if you go this link you can see the all security best

57
00:05:13,450 --> 00:05:14,680
practices in IAM.

58
00:05:14,710 --> 00:05:17,560
In this page you can see lots of security best practices.

59
00:05:17,560 --> 00:05:21,310
That's very important to follow of our accounts.

60
00:05:21,310 --> 00:05:28,900
For example, you can see the topics in here lock away your place account root user access keys, grant

61
00:05:28,900 --> 00:05:34,630
list privileges, get started using permissions with the wealth management policies that we are that

62
00:05:34,630 --> 00:05:36,190
we will do in the next video.

63
00:05:36,490 --> 00:05:43,150
And you can see lots of security practices, best practices like use access levels, review permissions,

64
00:05:43,300 --> 00:05:49,720
enable multi-factor authentication and remove unnecessary credentials, use policy conditions and so

65
00:05:49,720 --> 00:05:50,050
on.

66
00:05:51,060 --> 00:05:51,420
So.

67
00:05:51,420 --> 00:05:56,880
But for our course, it is enough to create a user and give required permission under the root user

68
00:05:56,880 --> 00:05:57,520
account.

69
00:05:57,540 --> 00:06:02,250
So we will create and follow these best practices.

70
00:06:02,250 --> 00:06:03,120
In the next video.

71
00:06:03,120 --> 00:06:08,850
We will create a user and configure for the programmatic answers for and console access.
