AWS Security ChangesHomeSearch

AWS organizations: Note that backup policy IAM role must pre-exist in member accounts

Service: organizations · 2026-09-27 · Documentation medium

File: organizations/latest/userguide/services-that-can-integrate-backup.md · Type: iam

Summary

Adds a note stating the IAM role referenced by a backup policy must already exist in each member account, since Organizations does not create AWSBackupDefaultServiceRole, and jobs will fail otherwise.

Security assessment

Documents IAM role prerequisites for backup policies across member accounts, which is security-adjacent operational guidance about role provisioning rather than a specific vulnerability fix.

Evidence

The IAM role that the backup policy references must already exist in each member account that the policy applies to. AWS Organizations does not create this role in member accounts.

Diff

diff --git a/organizations/latest/userguide/services-that-can-integrate-backup.md b/organizations/latest/userguide/services-that-can-integrate-backup.md
index bb136a1af..6bf27aad6 100644
--- a//organizations/latest/userguide/services-that-can-integrate-backup.md
+++ b//organizations/latest/userguide/services-that-can-integrate-backup.md
@@ -17,0 +18,4 @@ You can [enable the backup policy type](./enable-policy-type.html) in your organ
+###### Note
+
+The IAM role that the backup policy references must already exist in each member account that the policy applies to. AWS Organizations does not create this role in member accounts. Enabling trusted access, attaching a backup policy, and creating a backup vault (including through the AWS CLI or an SDK) do not create the default AWS Backup role (`AWSBackupDefaultServiceRole`) in member accounts. Create the required role in each member account before the backup jobs run; otherwise the jobs can start but then fail. For more information, see [Default service role for AWS Backup](https://docs.aws.amazon.com/aws-backup/latest/devguide/iam-service-roles.html) in the _AWS Backup Developer Guide_.
+