1
00:00:00,840 --> 00:00:07,170
In this video, we are going to create a user account under the root user account and configure this

2
00:00:07,500 --> 00:00:10,380
user account for programmatic and console access.

3
00:00:10,980 --> 00:00:18,480
So basically we can follow these steps which explained step by step in this user, you can click and

4
00:00:18,480 --> 00:00:20,340
open the web page.

5
00:00:20,850 --> 00:00:30,360
You can see that in this article step by step, explaining what we will do when we are creating a user

6
00:00:30,360 --> 00:00:32,760
and I am user and give some access.

7
00:00:32,910 --> 00:00:36,150
So I will also follow during this video.

8
00:00:36,180 --> 00:00:38,550
Let me continue it together.

9
00:00:39,120 --> 00:00:42,750
But before that, let's review what we have done so far.

10
00:00:42,960 --> 00:00:49,170
Basically, we are going to create user specific account under the root user account, and we set that

11
00:00:49,170 --> 00:00:55,590
when we after activating our Adobe account, we have got only the root user account.

12
00:00:55,830 --> 00:01:02,820
And the first thing we should do creating a user under the root user account and use these user for

13
00:01:02,820 --> 00:01:05,670
daily usage of a management console.

14
00:01:05,970 --> 00:01:09,060
Even you have the only one user to use a second.

15
00:01:09,060 --> 00:01:15,510
Creating a specific dedicating user account is one of the first thing we should do follow after activate

16
00:01:15,510 --> 00:01:16,730
our account.

17
00:01:16,740 --> 00:01:23,010
This is the security based practice that we should follow, so we should create user specific IAM user

18
00:01:23,010 --> 00:01:29,310
account under the root user account that they have own login and password information because root user

19
00:01:29,310 --> 00:01:35,070
account has powerful access that can change your payment information, password information, removing

20
00:01:35,070 --> 00:01:37,080
users and lots of dangerous things.

21
00:01:37,440 --> 00:01:39,930
So we also need to programmatic access.

22
00:01:39,930 --> 00:01:47,100
We said that we need also programmatic access because programmatic access users in IAM is required if

23
00:01:47,100 --> 00:01:55,470
you want to control or access your services from the command line or xkcd from the programmatic way

24
00:01:55,470 --> 00:02:01,890
of interaction required to programmatic access into the IAM user definition, a programmatic access

25
00:02:01,890 --> 00:02:11,370
users will be given, the users will be have given the access kid and a separate access key which your

26
00:02:11,790 --> 00:02:16,530
sales tools will use to authenticate to a place and execute your commands.

27
00:02:16,620 --> 00:02:22,020
So it is important to giving a programmatic access when creating an IAM user.

28
00:02:22,170 --> 00:02:27,420
And when we are creating a user with the programmatic access, it will be given to us.

29
00:02:27,420 --> 00:02:32,040
A The will is access key ID and a secret access key.

30
00:02:32,070 --> 00:02:40,290
So these two case will be required when you are authenticated to a will via SLI in order to execute

31
00:02:40,290 --> 00:02:41,220
our commands.

32
00:02:41,940 --> 00:02:45,960
So let's log in to our root user and create our IAM user.

33
00:02:45,960 --> 00:02:48,060
Be together for that purpose.

34
00:02:48,240 --> 00:02:55,080
Please connect with the sign in page and log in with the root user account.

35
00:02:56,140 --> 00:02:58,480
Signing with the root user account.

36
00:03:00,320 --> 00:03:08,030
So we have look in the management console with our rotisserie account, which you already also created

37
00:03:08,030 --> 00:03:08,720
before.

38
00:03:08,810 --> 00:03:13,100
So in this second, I'm going to open the I am.

39
00:03:14,150 --> 00:03:15,920
Identity and access management.

40
00:03:15,950 --> 00:03:19,070
You can search in here and click this button.

41
00:03:20,450 --> 00:03:24,830
So then we go to the place am page.

42
00:03:24,830 --> 00:03:32,930
And in this page, as you can see that we can do some stuff regarding with the identity and access management.

43
00:03:32,930 --> 00:03:37,160
We have users role policies and identity providers, so on.

44
00:03:37,460 --> 00:03:42,560
So we basically follow the users, just click the user section.

45
00:03:43,500 --> 00:03:50,840
And as you can see that I have already created my iam user account under ma under my root user account.

46
00:03:50,850 --> 00:03:57,960
But also please you should create a new one in order to create any IAM user account, you should click

47
00:03:57,960 --> 00:04:00,030
the add user button in here.

48
00:04:00,480 --> 00:04:02,310
Just click add user button.

49
00:04:03,430 --> 00:04:11,130
And enter the username what you would like to follow the course because during the course we will always

50
00:04:11,320 --> 00:04:14,080
using these IAM users for that purpose.

51
00:04:14,080 --> 00:04:21,820
Let me give the name the name user and this is the important part.

52
00:04:21,820 --> 00:04:31,570
We are going to select a double access type and we should check the access key and password both these

53
00:04:31,570 --> 00:04:37,960
checkbox, the access key programmatic access checkbox in access type section and the console access.

54
00:04:38,170 --> 00:04:41,590
The important part is we should select both of them.

55
00:04:42,650 --> 00:04:43,250
Okay.

56
00:04:43,640 --> 00:04:44,690
So let me explain.

57
00:04:44,690 --> 00:04:46,610
The first programmatic axis.

58
00:04:46,910 --> 00:04:54,320
Programmatic axis gives you access key ID and secret access key ID in order to interact resources with

59
00:04:54,320 --> 00:05:01,520
programmatically like a CLI SDK, cloud formation and CDK, we will use these tools during the course.

60
00:05:01,520 --> 00:05:04,730
So that's why it is important to give programmatic access.

61
00:05:04,790 --> 00:05:10,640
So during the course we will develop our microservice architecture via programmatically.

62
00:05:10,640 --> 00:05:17,060
That's why we should give these programmatic access and also provide the console management access and

63
00:05:17,390 --> 00:05:18,800
management console access.

64
00:05:18,920 --> 00:05:25,760
It is also important, of course, because we will log in our management console with the user specific

65
00:05:25,760 --> 00:05:33,290
account and follow the course with the specific user on the management console so you can give some

66
00:05:33,290 --> 00:05:36,680
custom passwords and don't record for the renewal.

67
00:05:37,130 --> 00:05:45,650
This is for the renewal and we can give some custom password account and it can give.

68
00:05:51,550 --> 00:05:52,450
Okay.

69
00:05:57,900 --> 00:05:58,210
Okay.

70
00:05:58,260 --> 00:06:05,640
You can click after you define a console password, you can click the next permission button.

71
00:06:06,270 --> 00:06:15,420
So now it is important and we are going to set permissions since we will use this user for our Udemy

72
00:06:15,420 --> 00:06:16,050
course.

73
00:06:16,050 --> 00:06:22,710
I would like to give administrator access to this user, but if you create this user for someone else,

74
00:06:22,710 --> 00:06:27,450
you should give more specific permissions by defining the policies.

75
00:06:27,960 --> 00:06:32,400
So click the attach existing policies directly top.

76
00:06:32,400 --> 00:06:41,400
You can click this one because we will attach the existing policies directly so you can see the administrator

77
00:06:41,400 --> 00:06:50,250
access and you should check this box in order to give the administrator access to this on the checkbox

78
00:06:50,400 --> 00:06:53,520
of access to policies that you want to assign to user.

79
00:06:53,670 --> 00:06:59,400
But if you create for other users, for example, you can specify custom permissions like only lambda

80
00:06:59,400 --> 00:07:06,570
execution or three, you can, for example, you can search for the lambda and you can give on lambda

81
00:07:06,570 --> 00:07:10,620
full access or read on access or execution, basic execution role.

82
00:07:10,650 --> 00:07:17,520
Or basically you can give only a three full access or three upload or read on the access to.

83
00:07:17,520 --> 00:07:25,380
But since we are using the course with the one specific user specific dedicated account, it is good

84
00:07:25,380 --> 00:07:29,550
to follow with the administrator access for our IAM user.

85
00:07:29,730 --> 00:07:35,160
So after check selected this administrator access, click the next button.

86
00:07:35,990 --> 00:07:42,590
And we don't define any tech and just click the next button and reveal your user.

87
00:07:42,710 --> 00:07:50,240
The username is new user and you can specify what you want and we have defined the passwords and the

88
00:07:50,240 --> 00:07:52,280
important part is the permission.

89
00:07:52,280 --> 00:07:56,780
We give the permission with the manage policy, which is the administrator access.

90
00:07:57,140 --> 00:08:02,210
And you can find that the created user see access case.

91
00:08:02,210 --> 00:08:06,200
Let me click the create button and see what we are going to do.

92
00:08:08,550 --> 00:08:15,180
After created, you will see the success message and also see this information is very important.

93
00:08:16,050 --> 00:08:21,270
You can find your created user c access keys for the programmatic access.

94
00:08:21,420 --> 00:08:28,980
We will use this access case when start to developing service applications and see the password secret

95
00:08:28,980 --> 00:08:31,560
access case in here with clicking the show button.

96
00:08:31,830 --> 00:08:33,270
So this is very important.

97
00:08:33,270 --> 00:08:40,830
Please copy these to information into your textbox or somewhere else because we will follow these.

98
00:08:41,130 --> 00:08:48,120
We will follow when authenticating to a double or account via a double click and cdcc.

99
00:08:48,120 --> 00:08:55,140
So that's why it is important we have successfully created our user specific account.

100
00:08:55,380 --> 00:08:59,550
So now you can also sign in with this account, right?

101
00:08:59,550 --> 00:09:06,690
So before go to the signing page, don't forget to get this account ID and the secret access key you

102
00:09:06,690 --> 00:09:09,630
can see on the right of this page.

103
00:09:10,640 --> 00:09:13,250
And also you can define alias for the account.

104
00:09:13,280 --> 00:09:14,950
I would like to show one more thing.

105
00:09:14,960 --> 00:09:21,280
You can see the account I.D. in here and also you can define the alias for this account.

106
00:09:21,290 --> 00:09:27,410
But these are the main information when you follow the during the course, the account ID, the access

107
00:09:27,410 --> 00:09:32,520
case, your user and password and secret access case, we have created the sub user account.

108
00:09:32,540 --> 00:09:33,890
It is very important.

109
00:09:34,010 --> 00:09:41,390
So now I'm going to go to signing page again and provide the newly created user credentials.

110
00:09:41,690 --> 00:09:48,260
Let me create a new a will start Amazon.com and see signing the console page.

111
00:09:48,860 --> 00:09:57,350
And now I'm going to look at the root user account and I would like to sign in with the I am user,

112
00:09:57,530 --> 00:10:01,760
so I am user is required to account ID.

113
00:10:02,210 --> 00:10:06,230
I have short account ID in the previous section.

114
00:10:06,230 --> 00:10:14,180
You can see in here, of course this is lost, but you can get the account ID from the right top of

115
00:10:14,180 --> 00:10:17,420
the page from the previous root user account.

116
00:10:17,420 --> 00:10:19,970
And after that you should define the account ID in here.

117
00:10:20,060 --> 00:10:24,290
I have specified the alias so that's why I can give the.

118
00:10:24,900 --> 00:10:28,120
The name of this alias of the account.

119
00:10:28,120 --> 00:10:29,110
ID account.

120
00:10:29,140 --> 00:10:30,550
Alias I have defined.

121
00:10:30,550 --> 00:10:35,710
But you should put in here two digit number as a account number.

122
00:10:35,800 --> 00:10:43,090
So after that, we should create a we should log in with the iam new user and I have a.

123
00:10:43,930 --> 00:10:48,040
Username is a user and I'm specifying.

124
00:10:49,330 --> 00:10:52,720
My password and click the sign up button.

125
00:10:55,850 --> 00:10:56,570
Okay.

126
00:10:56,900 --> 00:10:57,680
Very good.

127
00:10:57,710 --> 00:11:05,150
We are on the management console and login with the created iam specific user and I would like to switch

128
00:11:05,150 --> 00:11:06,560
the console home.

129
00:11:07,280 --> 00:11:07,610
Okay.

130
00:11:07,610 --> 00:11:08,270
Very good.

131
00:11:08,360 --> 00:11:12,770
So we will follow the whole course with this newly created user.

132
00:11:12,890 --> 00:11:16,160
So that's why please keep these account live and activate it.

133
00:11:16,190 --> 00:11:22,380
It is important because we will follow the the whole course with newly created users.

134
00:11:22,400 --> 00:11:30,320
I'm following with the Tosca, the the previous IAM account, but I will create this new user in order

135
00:11:30,320 --> 00:11:32,660
to show the whole process to you.

136
00:11:33,550 --> 00:11:37,570
And please keep this user account live and activated.

137
00:11:37,570 --> 00:11:44,260
As you can see that we have followed the security best practices and create specific IAM user and configure

138
00:11:44,260 --> 00:11:48,340
for the programmatic and management console access.

139
00:11:48,520 --> 00:11:51,360
So we will follow the course with these users.

140
00:11:51,370 --> 00:11:57,610
And in the next video I will explain what is the access types and what is the difference between programmatic

141
00:11:57,610 --> 00:11:59,530
and management console access.
