[ Applies to ] StorageGuard 9.x and later / Amazon Web Services (AWS) accounts / AWS IAM
StorageGuard collects configuration data from an AWS environment by running read-only AWS SDK management API calls. This article describes the requirements and how to set up an IAM user with read-only access for the scan.
In this article
Requirements
| Requirement | Details |
|---|---|
| Region | The name of the target AWS Region. |
| Account ID | The AWS account ID. |
| Credentials | An access key ID and secret access key for an IAM user. |
| Permissions | The IAM user needs read-only (List and Read) permissions for the services StorageGuard scans. Examples of API calls used: S3.ListStorageLensConfigurations, IAM.ListGroupsForUser, and Backup.ListProtectedResources. |
| Network access | Connectivity from the StorageGuard server to AWS. |
Set up IAM access for the scan
The following procedures are a suggested way to give StorageGuard read-only access. Do them in order, in the IAM service of the AWS Management Console (on the Console Home page, select IAM).
1. Create a read-only policy
- In the navigation pane, select Policies, and then select Create policy.
- On the first page, set the following:
- Under Service, choose a service to grant access to, for example S3.
- Under Actions, select the List and Read access levels.
- Under Resources, enter a specific resource ARN, or select All resources.
- Select Next: Tags, and then Next: Review.
- Under Review policy, enter a Name for the policy.
- Select Create policy.
2. Create a user group
- In the navigation pane, select User groups, and then select Create group.
- Under User group name, enter a name for the group.
- Scroll to the bottom of the page, and select Create group.
3. Attach the policy to the group
- In the navigation pane, select User groups, and then select the group you created.
- Select the Permissions tab.
- Under Permissions policies, select Add permissions > Attach policies.
- Under Other permission policies, search for the policy you created, and select the check box next to it.
- Scroll down, and select Add permissions.
4. Create the IAM user
- In the navigation pane, select Users, and then select Add users.
- On the Specify user details page, enter a User name, and select Next.
- On the Set permissions page, select Next. You add permissions through the group in the next procedure.
- Select Create user.
5. Add the user to the group
- In the navigation pane, select User groups, and then select the group you created.
- On the Users tab, under Users in this group, select Add users.
- Search for the user you created, and select the check box next to it.
- Select Add users.
6. Create an access key
- In the navigation pane, select Users, and then select the user you created.
- On the Security credentials tab, under Access keys, select Create access key.
- On the Access key best practices & alternatives page, select Next.
- On the Set description tag page, select Create access key.
- On the Retrieve access keys page, copy the Access key and Secret access key, and store them securely.
- Select Done.
Note: AWS shows the secret access key only once, on the Retrieve access keys page. If you lose it, create a new access key.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.