This document provides an introduction to AWS Identity and Access Management (IAM). It discusses IAM concepts such as users, groups, policies and roles. It also covers best practices for IAM configuration including using groups to manage permissions, strong password policies, multi-factor authentication, and minimizing the use of the root account. The document outlines Cornell's Shibboleth integration for single sign-on to AWS and notes additional security considerations outside of IAM.