AWS Security ChangesHomeSearch

AWS mgn: Update MGN connector IAM policy examples and trust policy condition

Service: mgn · 2026-09-27 · Documentation medium

File: mgn/latest/ug/create-permissions-console.md · Type: iam

Summary

Replaces placeholder tokens with concrete example values and changes the trust relationship condition operator from StringLike to ArnLike for aws:SourceArn.

Security assessment

The trust policy condition for aws:SourceArn is corrected from StringLike to ArnLike, which is the appropriate operator for ARN matching and tightens the cross-account assume-role condition; this is IAM hardening guidance rather than a specific vulnerability fix.

Evidence

+                    "ArnLike": {

Diff

diff --git a/mgn/latest/ug/create-permissions-console.md b/mgn/latest/ug/create-permissions-console.md
index 53d9850c4..4cf714d1b 100644
--- a//mgn/latest/ug/create-permissions-console.md
+++ b//mgn/latest/ug/create-permissions-console.md
@@ -85 +85 @@ The following policies are attached to the role:
-The **MgnConnectorPolicy** inline policy contains the following permissions, where _ACCOUNT-ID_ is the account in which the role is created and _AWS_REGION_ is the Region in which you added the connector:
+The **MgnConnectorPolicy** inline policy contains the following permissions. In the example, replace `111122223333` with the ID of the account in which the role is created, and `us-east-1` with the Region in which you added the connector:
@@ -94 +94 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe
-                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:*"
+                "Resource": "arn:aws:mgn:us-east-1:111122223333:*"
@@ -99 +99 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe
-                "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*",
+                "Resource": "arn:aws:mgn:us-east-1:111122223333:connector/*",
@@ -109 +109 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe
-                "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_ACCOUNT-ID"
+                "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_111122223333"
@@ -114 +114 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe
-                "Resource": "arn:aws:secretsmanager:AWS_REGION:ACCOUNT-ID:secret:*",
+                "Resource": "arn:aws:secretsmanager:us-east-1:111122223333:secret:*",
@@ -125,2 +125,2 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe
-                    "arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client",
-                    "arn:aws:s3:::amazon-ssm-AWS_REGION/*"
+                    "arn:aws:s3:::aws-application-migration-service-us-east-1/latest/source-automation-client/linux/ssaf-client/ssaf_client",
+                    "arn:aws:s3:::amazon-ssm-us-east-1/*"
@@ -139,2 +139,2 @@ The **MgnConnectorPolicy** inline policy contains the following permissions, whe
-                    "arn:aws:logs:AWS_REGION:ACCOUNT-ID:log-group:/aws/ssm/*",
-                    "arn:aws:logs:AWS_REGION:ACCOUNT-ID:log-stream:*"
+                    "arn:aws:logs:us-east-1:111122223333:log-group:/aws/ssm/*",
+                    "arn:aws:logs:us-east-1:111122223333:log-stream:*"
@@ -185 +185 @@ The role is created with the following trust relationship, where _management-acc
-                        "aws:SourceAccount": "management-account-id"
+                        "aws:SourceAccount": "111122223333"
@@ -187,2 +187,2 @@ The role is created with the following trust relationship, where _management-acc
-                    "StringLike": {
-                        "aws:SourceArn": "arn:aws:mgn:*:management-account-id:*"
+                    "ArnLike": {
+                        "aws:SourceArn": "arn:aws:mgn:*:111122223333:*"
@@ -195 +195 @@ The role is created with the following trust relationship, where _management-acc
-                    "AWS": "arn:aws:iam::management-account-id:role/AWSApplicationMigrationConnectorManagementRole"
+                    "AWS": "arn:aws:iam::111122223333:role/AWSApplicationMigrationConnectorManagementRole"