AWS mgn: Removed MGNConnectorInstallerRole and updated role requirements
Summary
Documentation updated to remove obsolete MGNConnectorInstallerRole and clarify required IAM roles for MGN connector deployment scenarios.
Security assessment
The change consolidates IAM permissions into fewer roles, reducing potential misconfiguration risks and clarifying deployment requirements for secure access control.
Evidence
The **MGNConnectorInstallerRole** is no longer required. Its permissions are now included in the **AWSApplicationMigrationConnectorManagementRole** , whose credentials the connector installer obtains from the AWS Systems Manager agent through the SSM hybrid activation.
Diff
diff --git a/mgn/latest/ug/mgn-connector-permissions.md b/mgn/latest/ug/mgn-connector-permissions.md index 253df3def..c075ac499 100644 --- a//mgn/latest/ug/mgn-connector-permissions.md +++ b//mgn/latest/ug/mgn-connector-permissions.md @@ -13,2 +12,0 @@ To use MGN connector you must have these required IAM roles for individual accou - * **MGNConnectorInstallerRole** - @@ -17,2 +15 @@ To use MGN connector you must have these required IAM roles for individual accou - * **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** Needed in an individual account. Also needed in an organization, on _every_ account, including the management account. - + * **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** – Needed in _every_ account that contains source servers on which the connector installs agents. MGN supports cross-account scenarios. In an individual account setup this is the connector's own account. In an organization, the role is needed on _every_ account, including the management account. `management-account-id` is the ID of the account in which the connector is created. @@ -22 +18,0 @@ To use MGN connector you must have these required IAM roles for individual accou -**Individual account:** For an MGN connector in an individual account, create these roles as described in [Create roles manually](./create-permissions-manually.html). @@ -24 +20 @@ To use MGN connector you must have these required IAM roles for individual accou -**Multiple accounts:** If the MGN connector manages source servers from multiple accounts, set up the global view feature and set up your AWS Organization, as described in [Manage large-scale migrations with global view](./global-view.html). After you set up your AWS Organization: +###### Note @@ -26 +22 @@ To use MGN connector you must have these required IAM roles for individual accou - 1. Create the MGNConnectorInstallerRole and the AWSApplicationMigrationConnectorManagementRole as described in [Create roles manually](./create-permissions-manually.html). +The **MGNConnectorInstallerRole** is no longer required. Its permissions are now included in the **AWSApplicationMigrationConnectorManagementRole** , whose credentials the connector installer obtains from the AWS Systems Manager agent through the SSM hybrid activation. If you created the **MGNConnectorInstallerRole** previously, it is no longer used. @@ -28 +24 @@ To use MGN connector you must have these required IAM roles for individual accou - 2. Configure the CloudFormation StackSet to create the AWSApplicationMigrationConnectorSharingRole_`management-account-id` role per management account. Use the template "Enable Application Migration Service Connector access". Instructions are in [Deploy role using a CloudFormation template ](./CloudFormation_Template.html). +You can create these roles in the following ways: @@ -29,0 +26 @@ To use MGN connector you must have these required IAM roles for individual accou +**MGN console (recommended):** When you add a connector using the MGN console, MGN can create the required roles for you, in an individual account or across all member accounts of your AWS Organization. For details about the roles the console creates, see [Create roles using the MGN console](./create-permissions-console.html). @@ -30,0 +28 @@ To use MGN connector you must have these required IAM roles for individual accou +**Individual account:** For an MGN connector in an individual account, create these roles as described in [Create roles manually](./create-permissions-manually.html). @@ -31,0 +30 @@ To use MGN connector you must have these required IAM roles for individual accou +**Multiple accounts:** If the MGN connector manages source servers from multiple accounts, set up the global view feature and set up your AWS Organization, as described in [Manage large-scale migrations with global view](./global-view.html). After you set up your AWS Organization, configure the CloudFormation StackSet to create the **AWSApplicationMigrationConnectorSharingRole_`management-account-id`** role in member accounts. Instructions are in [Deploy role using a CloudFormation template](./CloudFormation_Template.html). @@ -39 +38 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -Architecture overview +Setup instructions @@ -41 +40 @@ Architecture overview -Create roles manually +Create roles using the console