Configure access using temporary credentials for trusting AWS member accounts
Configure the access to AWS member accounts using the management account as their trusted account using the IAM role.
Before you begin
- Familiarize yourself with the Amazon documentation on Creating a role to delegate permissions to an IAM user.
- Ensure that you know which AWS member accounts are assigned to the same management account. You use the management account for configuring temporary credentials for cloud discovery using IAM roles.
- Set up the AWS management and the member accounts as covered in Set up AWS service accounts.
Role required: discovery_admin or sn_cmp.cloud_admin (for Cloud Provisioning and Governance)
About this task
You can configure access to member accounts, where members rely on their management account. It doesn't matter if the management account itself uses permanent or temporary credentials.
Procedure
What to do next
- Navigate to , and select the AWS account you created earlier as described in Set up AWS service accounts.
- Select the trusting account that you configured with the IAM role.
- Under Related Links, click Discover Datacenters.
- Navigate to , and then click the AWS tab.
- Check that the dashboard shows discovered resources for the account that you associated with the newly created AWS credentials.