Cloud infrastructure teams often focus on traditional security measures like CSPM, DLP, and network protection. However, there are hidden aspects of cloud infrastructure that warrant attention to ensure a robust and secure environment. In this article, we take a deep dive into the lesser-known quirks of AWS Identity and Access Management (IAM) roles and instance profiles, revealing unexpected behaviors that could impact security and resource management. Our exploration uncovers surprising findings when modifying IAM roles and instance profiles, such as the persistence of role credentials even after removing a role from an instance profile, the discrepancies in credential refresh timings, and the survival of instance profiles after role deletion. We also discuss the implications of these behaviors on security and resource management in AWS ecosystems, highlighting the importance of understanding and managing IAM roles and instance profiles correctly. Join us as we unravel the mysteries of AWS IAM roles and instance profiles, equipping you with the knowledge to guard your cloud environment against hidden threats and ensure a secure, efficient infrastructure.