IAM allows you to manage users and their level of access to the AWS Console.
+ centralized control your AWS account
+ shared access to your AWS account
+ granular permissions
+ identity federation (including Active Directory, Fb, Linkedin, etc)
- multifactor authen