---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Configure access using permanent credentials

# Configure access to the AWS accounts using permanent AWS credentials {#aws-create-creds-cloud-mgt__title-aws-create-creds}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery and Cloud Provisioning and Governance, you first create a user with programmatic access in the AWS Management Console. You then securely store the credentials in a service account at ServiceNow AI Platform.

## Before you begin

Roles required:

* AWS Management Console administrator
* For Cloud Discovery: discovery_admin
* For Cloud Provisioning and Governance: admin or sn_cmp.cloud_admin
{#aws-create-creds-cloud-mgt__ul_xnz_4wv_ndb}

## About this task

Cloud providers often use different names for accounts, regions, and credential settings. Because the ServiceNow application supports several cloud providers, the app uses general-purpose names for the settings.

## Procedure

1. **Optional:** To create a user for Cloud Provisioning and Governance (for programmatic access to your AWS resource and billing data), perform the following steps.
   1. On the AWS Management Console, navigate to Identity and Access Managements (IAM)Access ManagementUsers.
   2. On the IAM Resources portal, select Users.
   3. Select Add user.
   4. On the Details page, configure the user settings, and then select Next.  
      {#aws-create-creds-cloud-mgt__table_xks_hmm_h5b__entry__2}

      | Field | Description |
      |-|-|
      | User name | Name for the programmatic user. For example, <kbd class="ph userinput">servicenowcloud</kbd>. |
      | Access type | Select Programmatic access. |
      [Table 1. Details page]

      {#aws-create-creds-cloud-mgt__table_xks_hmm_h5b}
   5. On the Permissions page, attach the user to a policy.  
      Configure the following settings and then select Next.{#aws-create-creds-cloud-mgt__table_k3c_n4v_ndb__entry__2}

      | Field | Description |
      |-|-|
      | Set permissions for \<user name\> | Select Attach existing policies directly. |
      | Attach one or more policies ... | Select the appropriate policy. Note: The AdministratorAccess policy has the most powerful permission level, including permission to provision cloud resources. The policy enables the same access that would be granted to the instance if you were not using IAM and used your AWS account Access Key ID and Secret Access Key. You might instead prefer to create a policy or combine multiple policies to grant the appropriate permission level. See [Control AWS access and permissions using policies](https://servicenow-prod.fluidtopics.net/LQikZk4dqXG0SqXIyUOUGw "Configure policies with the necessary level of permissions to provide access to the AWS resources for Cloud Discovery and Cloud Provisioning and Governance.") for details. |
      [ ]

      {#aws-create-creds-cloud-mgt__table_k3c_n4v_ndb}
   6. On the Review page, verify your selections and then select Create user.
   7. On the Security Credentials page, copy the secret access key and the access key ID.  
      Important:  
      Do not leave the page until you have completed both steps. The Secret access key value does not appear again. You need to paste the values that you generate in these steps into a Cloud Provisioning and Governance form.
      1. Select Show to display the Secret access key. Copy the value.
      2. Select Download .csv to save the CSV-format file that contains the user name, Access key ID, and the Secret access key value. You create the file as a backup in the case that you lose the values. Verify that the file was created and then store the file securely.
      {#aws-create-creds-cloud-mgt__ol_lq1_rsv_ndb}
   {#aws-create-creds-cloud-mgt__substeps_uwb_xpb_jpb}
2. On the ServiceNow AI Platform, configure AWS credentials.
   1. In the ServiceNow instance, navigate to DiscoveryCredentials.
   2. Select New, select AWS Credentials, enter a unique and meaningful Name (for example, <kbd class="ph userinput">Cloud Provisioning Account</kbd>), and then fill in the form.  
      {#aws-create-creds-cloud-mgt__table_jsq_gxn_jw__entry__2}{#aws-create-creds-cloud-mgt__ph_aws-entry-name-desc}{#aws-create-creds-cloud-mgt__ph_aws-entry-active-desc}{#aws-create-creds-cloud-mgt__ph_aws-key-id-desc}{#aws-create-creds-cloud-mgt__ph_aws-entry-secret-key-desc}

      | Field | Input value |
      |-|-|
      | Name | Unique and descriptive name for the AWS credentials. |
      | Active | Option to use the credential. |
      | Access Key ID | The Access key ID that you generated on the AWS Management Console, such as: APIAIOSFODNN7EXAMPLE. |
      | Secret access key | The Secret access key that you generated on the AWS Management Console, such as: wPalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY. |
      [Table 2. AWS Credentials form fields]

      {#aws-create-creds-cloud-mgt__table_jsq_gxn_jw}
   3. Select Update or Submit.
   {#aws-create-creds-cloud-mgt__substeps_kvg_qw2_shc}
{#aws-create-creds-cloud-mgt__steps_fsy_zfd_yy}

## What to do next

Create an AWS service account on the ServiceNow AI Platform. For more information, see [Create AWS service accounts](https://servicenow-prod.fluidtopics.net/CvTA68TY3ph_FRR49RbdPg "Create AWS service accounts on the ServiceNow AI Platform to access your AWS account during AWS discovery.").

*[\>]: and then


