Reference Guide
Cloud Infrastructure Entitleme...
CSP Account Definition
cloud service provider’s account should be defined under the cloud integration section aws, azure, and gcp are supported cloud service providers the permission list of the csp account to be entered into pam should be as follows • iam list users("iam\ listusers"), • iam list instance profiles("iam\ instanceprofiles"), • iam list mfa devices("iam\ listmfadevices"), • iam list groups for user("iam\ listgroupsforuser"), • iam list attached user policies("iam\ listattacheduserpolicies"), • iam list access keys("iam\ listaccesskeys"), • iam get access key last used("iam\ getaccesskeylastused"), • iam list roles("iam\ listroles"), • iam list attached role policies("iam\ listattachedrolepolicies"), • iam list role policies("iam\ listrolepolicies"), • iam list groups("iam\ listgroups"), • iam list attached group policies("iam\ listattachedgrouppolicies"), • iam list group policies("iam\ listgrouppolicies"), • iam list policies("iam\ listpolicies"), • s3 list buckets("s3\ listbuckets"), • s3 get bucket location("s3\ getbucketlocation") • s3 list objects v2("s3\ listobjectsv2") • s3 get bucket acl("s3\ getbucketacl") • s3 get bucket cors("s3\ getbucketcors") • s3 get bucket encryption("s3\ getbucketencryption") • s3 get bucket policy("s3\ getbucketpolicy") • s3 get bucket policy status("s3\ getbucketpolicystatus") • rds describe instances("rds\ describeinstances") • rds describe instances role("rds\ describeinstancesrole") • ec2 describe instances("ec2\ describeinstances") •ec2 describe instance roles("ec2\ describeiaminstanceprofileassociations")