AWS Security ChangesHomeSearch

AWS mgn: Automated IAM role creation and Secrets Manager integration for MGN connector

Service: mgn · 2026-08-31 · Documentation high

File: mgn/latest/ug/mgn-connector-setup-instructions.md · Type: iam,secrets

Summary

Restructured setup process to automate IAM role creation, use Secrets Manager for credentials, and clarify connector lifecycle.

Security assessment

Automating IAM role creation reduces misconfiguration risks, while using Secrets Manager for credentials improves secret management security.

Evidence

+  2. **IAM roles** – The MGN console will automatically create the required IAM roles in your account. For details about the roles created, see [Create roles using the MGN console](./create-permissions-console.html).

Diff

diff --git a/mgn/latest/ug/mgn-connector-setup-instructions.md b/mgn/latest/ug/mgn-connector-setup-instructions.md
index 0e0da5a02..490a7f143 100644
--- a//mgn/latest/ug/mgn-connector-setup-instructions.md
+++ b//mgn/latest/ug/mgn-connector-setup-instructions.md
@@ -6,0 +7,2 @@
+Connector reuse and lifecycle
+
@@ -11 +13,31 @@ NEW - You can now accelerate your migration and modernization with AWS Transform
-In order to set up your MGN connector, take the following steps:
+To add an MGN connector, click **Add MGN connector** , to open the Add MGN connector page. Set up your MGN connector by providing the following:
+
+  1. **Connector name** : The MGN connector name is used to identify the connector. This field is mandatory, and limited to 256 characters. The name must be unique (case-insensitive) per account per Region.
+
+  2. **IAM roles** – The MGN console will automatically create the required IAM roles in your account. For details about the roles created, see [Create roles using the MGN console](./create-permissions-console.html).
+
+     * **Automatic role generation:** The setup page will automatically generate these two roles in your account:
+
+       * **AWSApplicationMigrationConnectorManagementRole** – Used during agent installation to access credentials.
+
+       * **AWSApplicationMigrationConnectorSharingRole_ <ACCOUNT-ID>** – Contains permissions for agent installation.
+
+     * **IAM roles deployment scope:**
+
+       * **Individual account:** For an MGN connector in an individual account, the roles are created automatically.
+
+       * **Multiple accounts:** If the MGN connector manages source servers from multiple accounts, set up the global view feature and set up your AWS Organization, as described in [Manage large-scale migrations with global view](./global-view.html). Alternatively, you can download a CloudFormation template from the setup page to deploy the IAM roles yourself.
+
+  3. **SSM Hybrid Activation** – Create a 30-day SSM Hybrid Activation for secure communication between the connector and AWS Systems Manager. This activation enables the connector to register as a managed instance.
+
+  4. **Acknowledge and create resources** – Click to generate the selected resources.
+
+  5. **Installation command** – The setup page generates a one-line installation command with all necessary credentials and configuration.
+
+  6. **Connector installation** – Install the connector on a Linux machine in your environment. For information on the required Linux machine, see [Prerequisites](./mgn-connector-prerequisites.html).
+
+    1. Copy the installation link from the setup page.
+
+    2. SSH into your chosen Linux machine.
+
+    3. Paste and execute the installation command.
@@ -13 +45 @@ In order to set up your MGN connector, take the following steps:
-  1. Make sure your account has the required permissions as defined in [MGN connector permissions](./mgn-connector-permissions.html).
+    4. Wait for installation to complete (typically 2–3 minutes).
@@ -15 +47 @@ In order to set up your MGN connector, take the following steps:
-  2. If the MGN connector manages source servers from multiple accounts, set up the global view feature and set up your AWS Organization, following the instructions [here](./global-view.html).
+  7. **Register servers** – Go back to the MGN Connector page in the AWS Application Migration Service console and click on the MGN connector name. Go to "Register servers" to attach source servers with the MGN connector.
@@ -17 +49 @@ In order to set up your MGN connector, take the following steps:
-After you set up your AWS Organization, configure the CloudFormation StackSet to create the required role per management account. Use the template "Enable AWS Transform MGN Connector access". Full instructions are available [here](./setting-up-stacksets.html).
+  8. **Configure credentials** – Choose the source servers that you would like to install with the replication agent. Go to **Actions** and then **Register server credentials**. You can use an existing AWS Secrets Manager secret or create a new one. You can select single or multiple source servers that share the same secret and provide it in bulk operation. For more information, see [Register server credentials](./connector-register-server-credentials.html).
@@ -19 +51 @@ After you set up your AWS Organization, configure the CloudFormation StackSet to
-  3. If the MGN connector manages source servers from a single account, and both the MGN connector and the source servers belong to the same account: 
+  9. **Agent deployment** – Once credentials are configured and verified, select the source servers and go to **Actions** , then choose **Install replication agent**. You can follow the status of agent installation in the **Agent installed** column in the console or through the **Command history** page.
@@ -21 +53 @@ After you set up your AWS Organization, configure the CloudFormation StackSet to
-    1. After replacing the example account number **111122223333** with your account number, create a role using the following trust policy: 
+The deployment process for each server:
@@ -23 +55 @@ After you set up your AWS Organization, configure the CloudFormation StackSet to
-JSON
+    1. MGN connector sends deployment commands to the connector via SSM.
@@ -24,0 +57 @@ JSON
+    2. The connector retrieves credentials from AWS Secrets Manager.
@@ -26 +59 @@ JSON
-****
+    3. The connector connects to the source server using the configured credentials.
@@ -27,0 +61 @@ JSON
+    4. The connector validates that the source server meets all prerequisites required to run the replication agent.
@@ -29,12 +63 @@ JSON
-                {
-            "Version":"2012-10-17",
-            "Statement": [
-                {
-                    "Effect": "Allow",
-                    "Principal": {
-                        "AWS": "arn:aws:iam::111122223333:role/AWSApplicationMigrationConnectorManagementRole"
-                    },
-                    "Action": "sts:AssumeRole"
-                }
-            ]
-        }
+    5. The connector installs and configures the replication agent.
@@ -41,0 +65 @@ JSON
+    6. The connector verifies successful installation and connectivity.
@@ -43 +66,0 @@ JSON
-    2. Attach the **AWSApplicationMigrationAgentInstallationPolicy** policy to the Permission policies. 
@@ -45 +67,0 @@ JSON
-    3. Name the role **AWSApplicationMigrationConnectorSharingRole_ACCOUNT-ID** (replace **ACCOUNT-ID** with your account number). 
@@ -47 +68,0 @@ JSON
-  4. [Create a new MGN connector](./add-connector.html) on the MGN connectors page. 
@@ -48,0 +70 @@ JSON
+## Connector reuse and lifecycle
@@ -49,0 +72 @@ JSON
+When deploying agents for subsequent waves, you can reuse an existing connector or create a new one. MGN connector console page lists all connectors configured in your account, showing the connector name, attached server count, and last seen date.
@@ -50,0 +74 @@ JSON
+SSM Hybrid Activations expire after 30 days. The activation is required only for installing the connector on the Linux machine. Once the connector is installed, you can continue to use it to install replication agents on source servers even after the activation expires. If you need to install the connector on a new machine after the activation has expired, you need to create a new connector through the setup process.
@@ -58 +82 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please
-Deploy role using CloudFormation template
+Architecture overview
@@ -60 +84 @@ Deploy role using CloudFormation template
-Installing the MGN connector on a secured network
+IAM roles for connector