Granting specific resource permission with having to give admin password or access key.
Different, granular permissions can be specified. Safe creditians and permission for application to access other AWS resources such as S3 Bucket, Dynamo DB tables.
How to secure account from leak, risk of hacking
MFA(Multi-factor Authentication) can be used for extrac security. Also support for FIDO (fast identity online) Security.
CloudTrail can log info. about requests for resources in account - based on IAM identity.
Access of IAM from different platform/services
IAM can be accessed through console, CLI, SDK, and HTTPS API
Lack of understanding when using IAM Resources, identities
https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html