AWS Security ChangesHomeSearch

AWS mgn: Fix export role S3 permission from GetObject to PutObject

Service: mgn · 2026-09-27 · Security-related medium

File: mgn/latest/ug/export-main.md · Type: iam

Summary

The IAM policy example for the export feature now grants s3:PutObject instead of s3:GetObject, aligning the documented permission with the write behavior of exporting.

Security assessment

Corrects the documented IAM permission for the role used by the export feature: export writes objects, so the previously documented s3:GetObject was wrong and could have led users to grant an incorrect (or, if paired with other statements, unnecessary) S3 permission, a least-privilege/authorization accuracy issue.

Evidence

         "s3:PutObject"

Diff

diff --git a/mgn/latest/ug/export-main.md b/mgn/latest/ug/export-main.md
index ec6048adb..b81207587 100644
--- a//mgn/latest/ug/export-main.md
+++ b//mgn/latest/ug/export-main.md
@@ -37 +37 @@ In order to use the export feature, you will need to create a role with the foll
-         "s3:GetObject"
+         "s3:PutObject"