- Granting users the minimum permissions necessary to perform their tasks
- Allowing users to access all AWS services and resources
- Restricting access to AWS services based on geographic location
- Requiring users to authenticate with multi-factor authentication (MFA)