yes Manish, IAM is a service provided by AWS. It basically tracks what users have what permissions. They make sure every user has appropriate permissions to access the resources and nothing more than that. It controls both centralized and fine-grained -API resources plus management console. It creates and manages AWS users and groups.