Home > Storage > ObjectScale and ECS > Product Documentation > Deploying the Elastic Stack with Searchable Snapshots and Frozen Tier > Create the IAM User and buckets
Two buckets were created in the ECS environment: one for the snapshot data and a second for the frozen data. An IAM (Identity Access Management) object user was created with Full Access to both buckets.
ECS Identity and Access Management (IAM) enables you to have fine-grained and secure access to the ECS S3 resources. This functionality ensures that each access request to an ECS resource is identified, authenticated, and authorized.
An IAM user to be used for Elasticsearch S3 snapshots is created in the ‘elasticsearch’ namespace. Dell recommends a least permissions IAM Policy to use for the IAM user. See the Elastic site for more information about S3 permissions.
Buckets are containers for objects created in a namespace and are sometimes considered a logical container for sub-tenants. The snapshots will be uploaded to the buckets shown in the following figure..
ECS buckets can be created using the ECS Web Portal, REST API, or an S3 client such as S3browser or the AWS CLI.