AWS Security ChangesHomeSearch

AWS mgn: Updated MGN connector IAM roles with least privilege and removed installer role

Service: mgn · 2026-08-31 · Documentation high

File: mgn/latest/ug/create-permissions-manually.md · Type: iam

Summary

Removed MGNConnectorInstallerRole, updated AWSApplicationMigrationConnectorManagementRole policy to use account/region-specific ARNs, and added AWSApplicationMigrationConnectorSharingRole documentation.

Security assessment

The change replaces wildcard resource ARNs with account/region-specific ARNs, enforcing least privilege and reducing risk of unintended access to MGN resources.

Evidence

+                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*",

Diff

diff --git a/mgn/latest/ug/create-permissions-manually.md b/mgn/latest/ug/create-permissions-manually.md
index e35135011..92a6493e6 100644
--- a//mgn/latest/ug/create-permissions-manually.md
+++ b//mgn/latest/ug/create-permissions-manually.md
@@ -7 +7 @@
-MGNConnectorInstallerRoleAWSApplicationMigrationConnectorManagementRole
+AWSApplicationMigrationConnectorManagementRoleAWSApplicationMigrationConnectorSharingRole_management-account-id
@@ -13 +13 @@ NEW - You can now accelerate your migration and modernization with AWS Transform
-To create permissions manually, you create the MGNConnectorInstallerRole to install the MGN Connector and the AWSApplicationMigrationConnectorManagementRole needed to enable the connector to run. The connector assumes the AWSApplicationMigrationConnectorSharingRole_`management-account-id` role as needed, for example, to install the replication agent on a source server.
+To create permissions manually, you create the **AWSApplicationMigrationConnectorManagementRole** needed to install and run the connector. The connector assumes the **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** role as needed, for example, to install the replication agent on a source server.
@@ -15 +15 @@ To create permissions manually, you create the MGNConnectorInstallerRole to inst
-## Create the MGNConnectorInstallerRole
+###### Note
@@ -17 +17 @@ To create permissions manually, you create the MGNConnectorInstallerRole to inst
-The **MGNConnectorInstallerRole** role is used to install the Connector. The user or identity that installs the Connector will require permission to assume this role. 
+The **MGNConnectorInstallerRole** is no longer required and does not need to be created. The permissions to register the connector (`mgn:CreateConnector` and `mgn:TagResource`) are included in the **MgnConnectorPolicy** below. The connector installer obtains the **AWSApplicationMigrationConnectorManagementRole** credentials from the AWS Systems Manager agent, which is registered using the SSM hybrid activation.
@@ -19,5 +19 @@ The **MGNConnectorInstallerRole** role is used to install the Connector. The use
-To create the role:
-
-  1. Create a policy from the following JSON: 
-
-JSON
+## AWSApplicationMigrationConnectorManagementRole
@@ -24,0 +21 @@ JSON
+The **AWSApplicationMigrationConnectorManagementRole** role is the role that is assumed by the Connector. The connector installer uses this role's credentials, provided by the AWS Systems Manager agent, to register the connector with MGN.
@@ -26 +23 @@ JSON
-****
+To create the role:
@@ -27,0 +25 @@ JSON
+  1. After replacing **ACCOUNT-ID** with your account number, and **AWS_REGION** with the connector region, create a policy from the following JSON:
@@ -33,4 +31,7 @@ JSON
-                "Action": [
-                    "mgn:TagResource"
-                ],
-                "Resource": "arn:aws:mgn:*:*:connector/*",
+                "Action": "mgn:CreateConnector",
+                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:*",
+                "Effect": "Allow"
+            },
+            {
+                "Action": "mgn:TagResource",
+                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*",
@@ -44,39 +44,0 @@ JSON
-            {
-                "Action": [
-                    "mgn:CreateConnector"
-                ],
-                "Resource": "*",
-                "Effect": "Allow"
-            }
-        ]
-    }
-    
-
-  2. Name the policy **MGNConnectorInstallerPolicy**. 
-
-  3. Create a role with your account as the trusted entity. Alternatively use a custom trust policy that will grant the user or identity that will install the Connector, permission to assume this role. 
-
-  4. Attach the **MGNConnectorInstallerPolicy** policy to the Permission policies. 
-
-  5. Name the role **MGNConnectorInstallerRole**. 
-
-
-
-
-## AWSApplicationMigrationConnectorManagementRole
-
-The **AWSApplicationMigrationConnectorManagementRole** role is the role that is initially assumed by the Connector. 
-
-To create the role:
-
-  1. After replacing **ACCOUNT-ID** with your account number, and **AWS_REGION** with the connector region, create a policy from the following JSON: 
-
-JSON
-    
-
-****
-    
-    
-        {
-        "Version":"2012-10-17",
-        "Statement": [
@@ -95 +57 @@ JSON
-                "Resource": "arn:aws:secretsmanager:*:*:secret:*",
+                "Resource": "arn:aws:secretsmanager:AWS_REGION:ACCOUNT-ID:secret:*",
@@ -100,3 +62,4 @@ JSON
-                "Resource":
-                    ["arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client",
-                    "arn:aws:s3:::amazon-ssm-AWS_REGION/*"],
+                "Resource": [
+                    "arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client",
+                    "arn:aws:s3:::amazon-ssm-AWS_REGION/*"
+                ],
@@ -136,6 +96,0 @@ JSON
-JSON
-    
-
-****
-    
-    
@@ -166,0 +121,58 @@ JSON
+## AWSApplicationMigrationConnectorSharingRole_`management-account-id`
+
+The **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** role is assumed by the **AWSApplicationMigrationConnectorManagementRole** to perform actions on source servers in member accounts. The role name includes the ID of the account that owns the connector (the management account), which allows a single member account to hold sharing roles for multiple management accounts.
+
+To create the role:
+
+  1. Create a policy from the following JSON: 
+    
+        {
+        "Version": "2012-10-17",
+        "Statement": [
+            {
+                "Effect": "Allow",
+                "Action": "mgn:StartAgentless",
+                "Resource": "arn:aws:mgn:*:*:source-server/*"
+            }
+        ]
+    }
+
+  2. Name the policy **AWSApplicationMigrationAgentInstallationPolicy**. 
+
+  3. Create a role with the following trust relationship, where `management-account-id` is the account in which the connector was created: 
+    
+        {
+        "Version": "2012-10-17",
+        "Statement": [
+            {
+                "Effect": "Allow",
+                "Principal": {
+                    "Service": "mgn.amazonaws.com"
+                },
+                "Action": "sts:AssumeRole",
+                "Condition": {
+                    "StringEquals": {
+                        "aws:SourceAccount": "management-account-id"
+                    },
+                    "StringLike": {
+                        "aws:SourceArn": "arn:aws:mgn:*:management-account-id:*"
+                    }
+                }
+            },
+            {
+                "Effect": "Allow",
+                "Principal": {
+                    "AWS": "arn:aws:iam::management-account-id:role/AWSApplicationMigrationConnectorManagementRole"
+                },
+                "Action": "sts:AssumeRole"
+            }
+        ]
+    }
+
+  4. Attach the **AWSApplicationMigrationAgentInstallationPolicy** policy to the Permission policies. 
+
+  5. Name the role **AWSApplicationMigrationConnectorSharingRole_`management-account-id`**, replacing `management-account-id` with the ID of the account in which the connector was created. 
+
+
+
+
@@ -173 +185 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please
-IAM roles for connector
+Create roles using the console