AWS organizations: Note that backup policy IAM role must pre-exist in member accounts
Summary
Adds a note stating the IAM role referenced by a backup policy must already exist in each member account, since Organizations does not create AWSBackupDefaultServiceRole, and jobs will fail otherwise.
Security assessment
Documents IAM role prerequisites for backup policies across member accounts, which is security-adjacent operational guidance about role provisioning rather than a specific vulnerability fix.
Evidence
The IAM role that the backup policy references must already exist in each member account that the policy applies to. AWS Organizations does not create this role in member accounts.
Diff
diff --git a/organizations/latest/userguide/services-that-can-integrate-backup.md b/organizations/latest/userguide/services-that-can-integrate-backup.md index bb136a1af..6bf27aad6 100644 --- a//organizations/latest/userguide/services-that-can-integrate-backup.md +++ b//organizations/latest/userguide/services-that-can-integrate-backup.md @@ -17,0 +18,4 @@ You can [enable the backup policy type](./enable-policy-type.html) in your organ +###### Note + +The IAM role that the backup policy references must already exist in each member account that the policy applies to. AWS Organizations does not create this role in member accounts. Enabling trusted access, attaching a backup policy, and creating a backup vault (including through the AWS CLI or an SDK) do not create the default AWS Backup role (`AWSBackupDefaultServiceRole`) in member accounts. Create the required role in each member account before the backup jobs run; otherwise the jobs can start but then fail. For more information, see [Default service role for AWS Backup](https://docs.aws.amazon.com/aws-backup/latest/devguide/iam-service-roles.html) in the _AWS Backup Developer Guide_. +