List usersList the IAM users in the account, one page at a time. Tags and permissions boundaries are not included; use 'Get a user' for those.
Get a userGet one IAM user with its tags and permissions boundary. Leave the name empty to get the user this connection signs in as.
Create a userCreate an IAM user. It starts with no console password, no access keys and no permissions; add it to a group or attach a policy to grant some.
Tag a userAdd tags to an IAM user. A tag whose name already exists on the user is overwritten with the new value; other tags are kept.
Delete a userPermanently delete an IAM user. AWS refuses while anything is still attached: remove it from its groups and detach its policies first, and delete its access keys and password in the console.
List groupsList the IAM groups in the account, one page at a time.
Get a groupGet an IAM group and a page of the users in it.
Create a groupCreate an empty IAM group. Attach policies to it in the IAM console, then add users with 'Add user to group'.
Delete a groupPermanently delete an IAM group. AWS refuses while it still has members or attached policies.
Add user to groupAdd an IAM user to a group, giving it the group's permissions. A user can be in up to 10 groups.
Remove user from groupRemove an IAM user from a group.
List a user's groupsList the IAM groups a user belongs to.
List rolesList the IAM roles in the account, including AWS's own service-linked roles. Tags, permissions boundaries and last use are not included; use 'Get a role' for those.
Get a roleGet one IAM role: its trust policy, tags, permissions boundary and when it was last used.
List policiesList managed policies: AWS's own, the ones made in this account, or both. AWS manages over a thousand, so narrow it with the filters or page through.
Attach policy to userAttach a managed policy to an IAM user, granting what it allows. A user can have up to 10 managed policies.
Detach policy from userDetach a managed policy from an IAM user. The policy itself is kept.
List a user's policiesList the managed policies attached directly to an IAM user. Policies it gets through its groups are not included.
List access keysList a user's access keys: ID, status and creation date. AWS never shows a secret access key again after it is created.
Update an access keyActivate or deactivate a user's access key, for example to suspend a leaked key without deleting it. This step will not deactivate the key this connection itself uses.