You can generate required access keys as an Amazon Identity and Access Management (IAM) user.

You can always generate access keys for your own account. If you have administrative privileges, you can also generate keys for other users.


  1. Log in as an IAM user.
  2. Go to the IAM service, and click the IAM user record for which to create access keys.
  3. Click the Security Credentials tab for that user.
    You must either be that user or have administrative privileges to create keys for other users.
  4. In the Access Keys section, click Manage Keys.
  5. Create and record the access keys.
    The secret key is not stored online after it is created.

What to do next

If you create a default guest group with the default permissions, the permissions do not include read access to the Elastic Map Reduce (EMR) service. You must use the IAM console to add the elasticmapreduce:DescribeJobFlows permission.