AWS Security ChangesHomeSearch

AWS mgn: Fix syntax of MGN agent role trust policy example

Service: mgn · 2026-09-27 · Documentation medium

File: mgn/latest/ug/mgn-initialize-api.md · Type: iam

Summary

Added the missing closing brace to the AWSApplicationMigrationAgentRole trust policy JSON example in the initialize-API prerequisites table, making the identity-based trust policy valid so it correctly shows the sts:SourceIdentity 's-*' and aws:SourceAccount condition keys that restrict who may assume the role.

Security assessment

The changed line is an IAM role trust policy containing least-privilege conditions: trusting only 'mgn.amazonaws.com' as a service principal, constraining assumed-role sessions with sts:SourceIdentity 's-*', and using aws:SourceAccount to prevent confused-deputy cross-account abuse. The edit is a JSON syntax correction (missing '}') rather than a fix for a disclosed vulnerability, but the example documents a security-relevant trust-policy boundary for the migration agent role.

Evidence

+**AWSApplicationMigrationAgentRole** | "mgn.amazonaws.com" | ["sts:AssumeRole", "sts:SetSourceIdentity"] | {"StringLike": {"sts:SourceIdentity": "s-*", "aws:SourceAccount": "<SOURCE-ACCOUNT-ID>"}}  

Diff

diff --git a/mgn/latest/ug/mgn-initialize-api.md b/mgn/latest/ug/mgn-initialize-api.md
index 6b5087229..4eca08c66 100644
--- a//mgn/latest/ug/mgn-initialize-api.md
+++ b//mgn/latest/ug/mgn-initialize-api.md
@@ -57 +57 @@ Role name | Trusted entities
-**AWSApplicationMigrationAgentRole** | "mgn.amazonaws.com" | ["sts:AssumeRole", "sts:SetSourceIdentity"] | {"StringLike": {"sts:SourceIdentity": "s-*", "aws:SourceAccount": "<SOURCE-ACCOUNT-ID>"}  
+**AWSApplicationMigrationAgentRole** | "mgn.amazonaws.com" | ["sts:AssumeRole", "sts:SetSourceIdentity"] | {"StringLike": {"sts:SourceIdentity": "s-*", "aws:SourceAccount": "<SOURCE-ACCOUNT-ID>"}}