AWS managedservices medium security documentation change
Summary
Updated VM Import/Export access instructions with new change type and instance profile requirements
Security assessment
Introduces more specific IAM controls (ct-117rmp64d5mvb) for instance profile creation, improving access management security
Diff
diff --git a/managedservices/latest/onboardingguide/vm-im-ex.md b/managedservices/latest/onboardingguide/vm-im-ex.md index 47cd9fe3f..28c48fbcf 100644 --- a//managedservices/latest/onboardingguide/vm-im-ex.md +++ b//managedservices/latest/onboardingguide/vm-im-ex.md @@ -36 +36 @@ An additional role, the **VM Import/Export Service** role, is required for the s - * Note: VM Import/Export is not accessible through the AWS console. The service can only be accessed through the AWS CLI, AWS Tools for PowerShell, and the AWS SDKs. A **VM Import/Export enabled** role must be requested by an AMS RFC (Management | Other | Other | Create), and then you have to access the service directly with the previously mentioned tools. Alternatively, you can request an instance profile by request for change (RFC, ct-19jq3ulr3g9zg) through which the tools can perform commands from an instance. + * VM Import/Export isn't accessible through the AWS console. You must access this service through the AWS CLI, AWS Tools for PowerShell, or the AWS SDKs. Or, you can request an instance profile by submitting change type ct-117rmp64d5mvb: Deployment | Advanced stack components | Identity and Access Management (IAM) | Create EC2 instance profile. This instance profile allows the tools to perform commands from an instance.