AWS Security ChangesHomeSearch

AWS managedservices medium security documentation change

Service: managedservices · 2025-09-28 · Security-related medium

File: managedservices/latest/onboardingguide/vm-im-ex.md

Summary

Updated VM Import/Export access instructions with new change type and instance profile requirements

Security assessment

Introduces more specific IAM controls (ct-117rmp64d5mvb) for instance profile creation, improving access management security

Diff

diff --git a/managedservices/latest/onboardingguide/vm-im-ex.md b/managedservices/latest/onboardingguide/vm-im-ex.md
index 47cd9fe3f..28c48fbcf 100644
--- a//managedservices/latest/onboardingguide/vm-im-ex.md
+++ b//managedservices/latest/onboardingguide/vm-im-ex.md
@@ -36 +36 @@ An additional role, the **VM Import/Export Service** role, is required for the s
-  * Note: VM Import/Export is not accessible through the AWS console. The service can only be accessed through the AWS CLI, AWS Tools for PowerShell, and the AWS SDKs. A **VM Import/Export enabled** role must be requested by an AMS RFC (Management | Other | Other | Create), and then you have to access the service directly with the previously mentioned tools. Alternatively, you can request an instance profile by request for change (RFC, ct-19jq3ulr3g9zg) through which the tools can perform commands from an instance.
+  * VM Import/Export isn't accessible through the AWS console. You must access this service through the AWS CLI, AWS Tools for PowerShell, or the AWS SDKs. Or, you can request an instance profile by submitting change type ct-117rmp64d5mvb: Deployment | Advanced stack components | Identity and Access Management (IAM) | Create EC2 instance profile. This instance profile allows the tools to perform commands from an instance.