An AWS account has resources and users. It also has an account-id
.
By default a root user is created, and this user has complete and unrestricted access to all resources in your AWS account.
AWS IAM is used to manage users (identity) and resource access (access management) on an AWS account.
All AWS resources have a unique identifier known as an ARN.