---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Set up AWS service accounts

# Set up AWS service accounts {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Amazon Web Services (AWS) service accounts.

## Verify the REST API Permissions {#setup-aws-service-accounts__section_onh_dcp_v2c}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available
quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#setup-aws-service-accounts__cloud-discovery-api-paragraph}
Ensure that you are familiar with the hierarchy of AWS service accounts in your environment. For example, if there are AWS Organizations, set up the management and member accounts at ServiceNow AI Platform to reflect that hierarchy. You can set up the AWS service accounts of the following types:

* Discrete account: Standalone account, with no management account.
* Management account: Management account that may or may not contain member accounts (subaccounts).  
  Note:  
  Some ServiceNow UI screens may refer to management accounts as master accounts.
* Member account: Subaccount that belongs with the (management) account.
{#setup-aws-service-accounts__ul_hnd_pkb_5hb}
* **[Access setup for AWS service accounts](https://servicenow-prod.fluidtopics.net/u50K4wELxZMtjj~alXnzVg)**   
  Cloud Discovery and Cloud Provisioning and Governance need access to resources in the Amazon Web Services (AWS) service accounts. Learn about different methods of configuring such access.
* **[Configure access to the AWS accounts using permanent AWS credentials](https://servicenow-prod.fluidtopics.net/7h~fNPL6B2QF6yjrpdw9Lg)**   
  To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery and Cloud Provisioning and Governance, you first create a user with programmatic access in the AWS Management Console. You then securely store the credentials in a service account at ServiceNow AI Platform.
* **[Create AWS service accounts](https://servicenow-prod.fluidtopics.net/CvTA68TY3ph_FRR49RbdPg)**   
  Create AWS service accounts on the ServiceNow AI Platform to access your AWS account during AWS discovery.
* **[Configure temporary credential access for trusted AWS accounts](https://servicenow-prod.fluidtopics.net/tnnDDMp~UwhC6f0GVUN4xg)**   
  Configure the trusting account whose resources need to be accessed, to rely on the trusted account using the Identity and Access Management (IAM) role.
* **[Configure credential-less access using trusted AWS accounts](https://servicenow-prod.fluidtopics.net/8Y0DgJeDNn0RUa5hrN1L5w)**   
  Set up a trusted credential-less account that other AWS accounts can rely on for access.
* **[Configure access for trusting AWS member accounts in trust chain](https://servicenow-prod.fluidtopics.net/PxepG0CfRHr~cJR77a3ilw)**   
  Configure access for AWS member accounts by using a trust chain from the accessor through the management account.
* **[Configure the MID Server for AWS IAM roles](https://servicenow-prod.fluidtopics.net/lhMYkC6JaBaGV2hHTqPjcg)**   
  Configure the MID Server to retrieve the temporary security credentials associated with an IAM role.
* **[Control AWS access and permissions using policies](https://servicenow-prod.fluidtopics.net/LQikZk4dqXG0SqXIyUOUGw)**   
  Configure policies with the necessary level of permissions to provide access to the AWS resources for Cloud Discovery and Cloud Provisioning and Governance.

