IAM not only enables control access of access to specific AWS resources, but can also specify constraints on the mode of access to AWS. For example, IAM permits conditions about access to AWS according to parameters such as the time of day, originating IP address or the use of SSL. Identity Federation enhances IAM by allowing users to access AWS resources without requiring an individual IAM user i