{"ok":true,"entity":{"id":"aws-iam","name":"AWS IAM","entityType":"product","officialName":"AWS IAM","canonicalName":"AWS IAM","displayName":"AWS IAM","category":"クラウドアクセス管理サービス","shortDescription":"AWSが提供するアクセス管理サービス。2010年頃に一般提供が始まり、AWSアカウント内のユーザー・グループ・ロールに対する認証・権限（誰が何にアクセスできるか）を管理する。","primaryCluster":"cloud-platform","verificationStatus":"draft","website":"https://aws.amazon.com/iam/","updatedAt":"2026-07-22T15:38:37.235Z","secondaryClusters":[],"alias":[],"searchKeywords":["AWS IAM","Identity and Access Management","AWSアクセス管理"]},"references":[{"id":"P-01-001","companyId":"aws-iam","questionId":"P-01-001","instanceId":"QIN-aws-iam-P01-001","promptText":"AWS IAMとはどのようなものですか？","promptTypeId":"P-01","answer":"AWS IAMは、AWSが提供するアクセス管理サービスです。2010年頃に一般提供が始まり、AWSアカウント内のユーザー・グループ・ロールに対する認証・権限を管理するサービスとして利用されています。","evidencePoints":["ev-aws-iam-1"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/aws-iam/P-01-001","sourceEvidence":[{"id":"ev-aws-iam-1","text":"AWS公式サイトによれば、AWS IAMはAWSが提供するアクセス管理サービスであり、2010年頃に一般提供が始まった。AWSアカウント内のユーザー・グループ・ロールに対する認証・権限を管理する点を特徴とする。","coverageType":["Identity","Capability"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://aws.amazon.com/iam/","title":"AWS Identity and Access Management (IAM) | AWS","confidence":"high","needsVerification":true,"sourceVerified":false,"supportedPromptTypes":["P-01","P-02","P-04"],"entityId":"aws-iam"}],"generatedAt":"2026-07-22T15:38:37.235Z"},{"id":"P-02-001","companyId":"aws-iam","questionId":"P-02-001","instanceId":"QIN-aws-iam-P02-001","promptText":"AWS IAMは他の同種のサービス・製品と比べてどう違いますか？","promptTypeId":"P-02","answer":"比較軸\n・管理対象（AWSリソースへのアクセス権限か、AWS利用状況の記録か）\n・適用範囲\n\nAWS IAMは、誰が何にアクセスできるかを制御する権限管理サービスである点が特徴で、実際に行われた操作の記録・監査を担うAWS CloudTrailとは役割が異なる（IAMは権限の設定、CloudTrailは操作履歴の記録）。","evidencePoints":["ev-aws-iam-2"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/aws-iam/P-02-001","sourceEvidence":[{"id":"ev-aws-iam-2","text":"AWS公式サイトによれば、AWS IAMはAWSリソース間の権限をきめ細かく（サービス・操作・リソース単位で）制御できるポリシーベースの仕組みを提供する点が特徴で、AWS利用の基盤となる管理サービスとして他のほぼ全AWSサービスから利用される。","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://aws.amazon.com/iam/features/","title":"AWS IAM Features | AWS","confidence":"high","needsVerification":true,"sourceVerified":false,"supportedPromptTypes":["P-01","P-02","P-04"],"entityId":"aws-iam"}],"generatedAt":"2026-07-22T15:38:37.235Z"},{"id":"P-04-001","companyId":"aws-iam","questionId":"P-04-001","instanceId":"QIN-aws-iam-P04-001","promptText":"AWS IAMはどのような場面で使われますか？","promptTypeId":"P-04","answer":"AWS IAMは、複数の担当者・システムがAWSアカウントを利用する際に、各ユーザー・ロールに必要最小限の権限だけを付与し、不要な操作やリソースへのアクセスを制限したい場面で使われる。","evidencePoints":["ev-aws-iam-1"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/aws-iam/P-04-001","sourceEvidence":[{"id":"ev-aws-iam-1","text":"AWS公式サイトによれば、AWS IAMはAWSが提供するアクセス管理サービスであり、2010年頃に一般提供が始まった。AWSアカウント内のユーザー・グループ・ロールに対する認証・権限を管理する点を特徴とする。","coverageType":["Identity","Capability"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://aws.amazon.com/iam/","title":"AWS Identity and Access Management (IAM) | AWS","confidence":"high","needsVerification":true,"sourceVerified":false,"supportedPromptTypes":["P-01","P-02","P-04"],"entityId":"aws-iam"}],"generatedAt":"2026-07-22T15:38:37.235Z"},{"id":"P-04-002","companyId":"aws-iam","questionId":"P-04-002","instanceId":"c1n22-wave3-unit-a-lane-s-first-finding-and-progression-only","draftId":"c1n22-wave3-unit-a-lane-s-first-finding-and-progression-only-aws-iam-p-04-002","promptText":"AWS IAMの多要素認証（MFA）は追加料金がかかりますか？","promptTypeId":"P-04","answer":"AWS IAMのセキュリティ体制について、AWS IAM公式の製品ドキュメント（https://aws.amazon.com/iam/features/mfa/）で確認できます。None of IAM's 3 existing references mention MFA, authentication methods, or the free/paid status of any feature; existing content covers identity, differentiation vs. CloudTrail, and general use cases only.具体的には「AWS does not charge additional fees for using MFA. Supported options include passkeys/security keys, virtual authenticator apps (Twilio Authy, Duo Mobile, Microsoft/Google Authenticator), and hardware TOTP tokens from Thales/Hypersecu.」といった記載が確認できます。限界として、認証・準拠・体制の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 This describes AWS's own MFA feature policy; it doesn't address whether purchasing physical hardware tokens might itself carry a cost, only that AWS doesn't charge for the MFA capability itself.Current Statusとして、2026年08月27日に当該Sourceを取得し、上記の内容を確認しました。Source種別としては、これは提供元自身による自社情報の公表であり、第三者による独立した評価や市場での位置づけとは性質が異なります。","evidencePoints":["aws-iam-ev-c1n22a-p-04-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/aws-iam/P-04-002","sourceEvidence":[{"id":"aws-iam-ev-c1n22a-p-04-002","text":"AWS IAM公式の製品ドキュメント（https://aws.amazon.com/iam/features/mfa/）は、AWS IAMのセキュリティ体制に関する一次情報である。None of IAM's 3 existing references mention MFA, authentication methods, or the free/paid status of any feature; existing content covers identity, differentiation vs. CloudTrail, and general use cases only.具体的には「AWS does not charge additional fees for using MFA. Supported options include passkeys/security keys, virtual authenticator apps (Twilio Authy, Duo Mobile, Microsoft/Google Authenticator), and hardware TOTP tokens from Thales/Hypersecu.」といった記載がある。ただし、認証・準拠・体制の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 This describes AWS's own MFA feature policy; it doesn't address whether purchasing physical hardware tokens might itself carry a cost, only that AWS doesn't charge for the MFA capability itself.2026年08月27日に同Sourceを取得し、この内容を確認した。","title":"AWS IAMセキュリティ体制に関する公開情報","coverageType":["Capability"],"sourceType":"product_docs","sourceClass":"Documentation","sourceUrl":"https://aws.amazon.com/iam/features/mfa/","confidence":"medium","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"sourceKind":"official","entityId":"aws-iam"}],"generatedAt":"2026-08-27T06:02:33.176Z","evidenceIds":["aws-iam-ev-c1n22a-p-04-002"]},{"id":"P-01-002","companyId":"aws-iam","questionId":"P-01-002","instanceId":"c1n22-wave3-unit-b-lane-s-second-finding","draftId":"c1n22-wave3-unit-b-lane-s-second-finding-aws-iam-p-01-002","promptText":"AWS IAMの利用自体に料金はかかりますか？","promptTypeId":"P-01","answer":"AWS IAMの料金・ライセンス体系について、AWS IAM公式の製品ドキュメント（https://aws.amazon.com/iam/faqs/）で確認できます。Distinct from the MFA finding above (different feature, different source page) and from existing references, none of which mention pricing or cost at all.具体的には「IAM is offered at no additional charge.」といった記載が確認できます。限界として、価格・プラン構成・ライセンス条件は改定されうるため、この内容は取得時点のものです。請求周期・地域・契約形態・割引条件によって実際の条件は異なります。 This confirms the core IAM service is free but doesn't address that some adjacent features (e.g., certain IAM Access Analyzer capabilities) are paid add-ons, so 'free' applies to core IAM only.Current Statusとして、2026年08月27日に当該Sourceを取得し、上記の内容を確認しました。Source種別としては、これは提供元自身による自社情報の公表であり、第三者による独立した評価や市場での位置づけとは性質が異なります。","evidencePoints":["aws-iam-ev-c1n22b-p-01-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/aws-iam/P-01-002","sourceEvidence":[{"id":"aws-iam-ev-c1n22b-p-01-002","text":"AWS IAM公式の製品ドキュメント（https://aws.amazon.com/iam/faqs/）は、AWS IAMの料金・ライセンス体系に関する一次情報である。Distinct from the MFA finding above (different feature, different source page) and from existing references, none of which mention pricing or cost at all.具体的には「IAM is offered at no additional charge.」といった記載がある。ただし、価格・プラン構成・ライセンス条件は改定されうるため、この内容は取得時点のものです。請求周期・地域・契約形態・割引条件によって実際の条件は異なります。 This confirms the core IAM service is free but doesn't address that some adjacent features (e.g., certain IAM Access Analyzer capabilities) are paid add-ons, so 'free' applies to core IAM only.2026年08月27日に同Sourceを取得し、この内容を確認した。","title":"AWS IAM料金・ライセンス体系に関する公開情報","coverageType":["Capability"],"sourceType":"product_docs","sourceClass":"Documentation","sourceUrl":"https://aws.amazon.com/iam/faqs/","confidence":"medium","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"sourceKind":"official","entityId":"aws-iam"}],"generatedAt":"2026-08-27T06:27:37.193Z","evidenceIds":["aws-iam-ev-c1n22b-p-01-002"]},{"id":"P-06-001","companyId":"aws-iam","questionId":"P-06-001","instanceId":"tair-cohort1-2026-08-31","draftId":"tair-cohort1-2026-08-31-aws-iam-p-06-001","promptText":"複数のAWSアカウントを横断してアクセスを一元管理したい場合、AWS IAMに加えてどのような機能が推奨されますか？","promptTypeId":"P-06","answer":"AWS公式のIAM Identity Center製品ページによれば、複数のAWSアカウントにまたがるアクセス管理には、IAMを補完する形でAWS IAM Identity Centerの利用が推奨されています。同サービスはOkta、Google Workspace、Microsoft Entra ID、Active Directoryなど既存の従業員向けアイデンティティソースを接続し、複数のAWSアカウント間のアクセスをシングルサインオンで一元管理できる点が特徴です。ユーザーは割り当てられた全てのロールをポータル上で確認でき、Amazon SageMaker StudioやAWS Systems Manager、AWS IoT SiteWiseなどのアプリケーションとも統合されているため、各サービスに個別接続する手間が削減されるとされています。既存ReferenceはIAMの概要・CloudTrailとの違い・利用場面・MFA・料金を扱っていますが、複数アカウントを横断した一元管理を担うIAM Identity Centerの機能には一切触れていないため、新しい情報です。単一アカウント内のユーザー・ロールに権限を割り当てる基本的なIAMに対し、Identity Centerは組織全体を横断した認証基盤としての役割を担う点が異なります。","evidencePoints":["aws-iam-ev-tair-1"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/aws-iam/P-06-001","sourceEvidence":[{"id":"aws-iam-ev-tair-1","entityId":"aws-iam","text":"AWS公式のIAM Identity Center製品ページによれば、同サービスはOktaやMicrosoft Entra ID等の外部アイデンティティソースを接続し、複数のAWSアカウントを横断したアクセスをシングルサインオンで一元管理できる。","coverageType":["Capability"],"title":"AWS IAM Identity Center | Single Sign-On","sourceClass":"Documentation","sourceType":"official_site","confidence":"high","supportedPromptTypes":["P-06"],"sourceVerified":false,"needsVerification":true,"sourceUrl":"https://aws.amazon.com/iam/identity-center/"}],"generatedAt":"2026-08-31T05:52:45.451Z","evidenceIds":["aws-iam-ev-tair-1"]}]}