Cloud IAM: STS, Roles, SCP, and P...
Cloud IAM: STS, Roles, SCP, and Policies
Sec Guy by Sec Guy
S4 · E2
Sep 17, 2026
04:17
Episode notes

A password can be stolen, but a temporary token expires. In this video, Sec Guy explains why Long-Term Access Keys are a "security smell" and how to replace them with IAM Roles and the STS (Security Token Service). We break down the critical difference between Identity-Based Policies (What I can do) and Resource-Based Policies (Who can access this bucket), and show you how to use SCPs (Service Control Policies) to create an unbreakable ceiling on permissions.

New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

[Exam Ready Route - FREE]

Pass your certification for $0.

✅ Training Videos & Practice Tests

✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

✅ Discord Access (Study sessions & Industry networking)

👉 Start Here:  ... 

Keywords
Comptia
SecGuy
Infosec
Cybersecurity Training
IT Certification
Cyber
Tech Podcast
Security+ SY0-701