AWS IAM中Identity与Entity的概念差异及本质区别咨询
IAM Identity vs Entity: Not Just Syntax, But Core Role Differences
Great question — this is one of those IAM terminology nuances that confuses almost everyone when they first dive into AWS permissions. Let’s break down why these terms exist and their actual differences, beyond just wording:
Core Definitions (Reframed for Clarity)
Identity: The Permission Container
- An Identity is an IAM resource designed to hold and manage permissions. That’s why it includes users, groups, and roles:
- Users: Individual permanent identities you assign permissions to
- Groups: Batch permission containers for users (they never initiate requests themselves)
- Roles: Permissions containers that can be "assumed" by other entities
- Only Identities can have policies attached because policies define what permissions exist — you’re assigning rules to a persistent identity framework, not a one-time session.
Entity: The Authentication Subject
- An Entity is the actual thing that AWS authenticates when a request comes in. It’s the "active" actor making the call, which includes:
- IAM users (when they log in directly with their credentials)
- Federated users (people coming from external systems like SAML or OAuth)
- Assumed IAM roles (the temporary session created when a user/entity takes on a role)
- Entities are transient in many cases (like role sessions) — they’re the live instance of an Identity being used to perform actions.
Why Your Observations Make Sense
Your notes about the overlap and differences are spot-on, and they all tie back to these core roles:
- Only Identity includes groups: Groups don’t make requests, so they never need to be authenticated as an Entity. They’re just a tool to manage Identity permissions at scale.
- Only Identities get policies: Policies are tied to the persistent permission framework, not the temporary session using it.
- AWS validates Entities, not Identities: When a request hits AWS, it needs to verify who is currently acting — that’s the Entity (e.g., a role’s temporary session), which maps back to an Identity to get its permissions.
Final Takeaway
This isn’t just a syntax quirk — it’s a separation of concerns in AWS’s permission model:
- Identity answers: "What permissions are available?"
- Entity answers: "Who is currently using those permissions?"
It’s a subtle but important distinction that helps AWS handle both persistent permission management and dynamic, temporary access scenarios smoothly.
内容的提问来源于stack exchange,提问作者Narin Luangrath
相关产品推荐
相关产品推荐

