{"id":5609,"date":"2018-11-23T05:39:31","date_gmt":"2018-11-23T05:39:31","guid":{"rendered":"https:\/\/www.devopsschool.com\/blog\/?p=5609"},"modified":"2021-11-17T09:24:21","modified_gmt":"2021-11-17T09:24:21","slug":"unerstanding-the-difference-between-aws-root-administrator-power-user","status":"publish","type":"post","link":"https:\/\/www.devopsschool.com\/blog\/unerstanding-the-difference-between-aws-root-administrator-power-user\/","title":{"rendered":"Understanding the difference between AWS Root, Administrator &#038; Power User?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5626\" src=\"https:\/\/www.devopsschool.com\/blog\/wp-content\/uploads\/2018\/11\/Understanding-AWS.png\" alt=\"\" width=\"400\" height=\"215\" srcset=\"https:\/\/www.devopsschool.com\/blog\/wp-content\/uploads\/2018\/11\/Understanding-AWS.png 400w, https:\/\/www.devopsschool.com\/blog\/wp-content\/uploads\/2018\/11\/Understanding-AWS-300x161.png 300w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/p>\n<p><strong>The AWS Account Root User<\/strong><br>\nWhen you first create an Amazon Web Services (AWS) account, you begin with a single sign-in identity that has complete access to all AWS services and resources in the account. This identity is called the AWS account root user and is accessed by signing in with the email address and password that you used to create the account.<\/p>\n<p><strong>Developer Power User<\/strong><br>\nThis is an IAM user by AWS managed policy name: PowerUserAccess. This provides full access to AWS services and resources, but does not allow management of Users and groups.This user performs application development tasks and can create and configure resources and services that support AWS aware application development.<\/p>\n<p>Policy description: This policy grants all actions for all AWS services and for all resources except AWS Identity and Access Management and AWS Organizations. It grants IAM permissions to create a service-linked role. This is required by some services that must access resources in another service, such as an Amazon S3 bucket. It grants Organizations permissions to view information about the user&#8217;s organization, including the master account email and organization limitations.<\/p>\n<p><strong>Administrator<\/strong><br>\nThis is a IAM user by AWS managed policy name: AdministratorAccess. This user has full access and can delegate permissions to every service and resource in AWS.<\/p>\n<p>Policy description: This policy grants all actions for all AWS services and for all resources in the account.<\/p>\n\n<div class=\"epyt-gallery\" data-currpage=\"1\" id=\"epyt_gallery_34433\"><figure class=\"wp-block-embed wp-block-embed-youtube is-type-video is-provider-youtube epyt-figure\"><div class=\"wp-block-embed__wrapper\"><iframe loading=\"lazy\"  id=\"_ytid_37096\"  width=\"760\" height=\"427\"  data-origwidth=\"760\" data-origheight=\"427\" src=\"https:\/\/www.youtube.com\/embed\/?enablejsapi=1&#038;autoplay=0&#038;cc_load_policy=0&#038;cc_lang_pref=&#038;iv_load_policy=1&#038;loop=0&#038;rel=1&#038;fs=1&#038;playsinline=0&#038;autohide=2&#038;theme=dark&#038;color=red&#038;controls=1&#038;disablekb=0&#038;\" class=\"__youtube_prefs__  no-lazyload\" title=\"YouTube player\"  data-epytgalleryid=\"epyt_gallery_34433\"  allow=\"fullscreen; accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen data-no-lazy=\"1\" data-skipgform_ajax_framebjll=\"\"><\/iframe><\/div><\/figure><div class=\"epyt-gallery-list\"><div>Sorry, there was a YouTube error.<\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>The AWS Account Root User When you first create an Amazon Web Services (AWS) account, you begin with a single sign-in identity that has complete access to all AWS services and resources in the account. This identity is called the AWS account root user and is accessed by signing in with the email address and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":5626,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","_joinchat":[],"footnotes":""},"categories":[5633],"tags":[1993,162,348,5139,5140,1662,412],"class_list":["post-5609","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aws","tag-administrator","tag-aws","tag-developer","tag-policy","tag-power","tag-root","tag-user"],"_links":{"self":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/5609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/comments?post=5609"}],"version-history":[{"count":4,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/5609\/revisions"}],"predecessor-version":[{"id":25561,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/5609\/revisions\/25561"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/media\/5626"}],"wp:attachment":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/media?parent=5609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/categories?post=5609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/tags?post=5609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}