Step 1 - Create IAM Role for Lookout Secure Cloud Access
- In the AWS console, click Roles and select Create role.
- Select Role Type: Another AWS Account.
-
For Account ID, obtain this ID from the Lookout DevOps team.
This is the account ID for the AWS account in which the tenant Management Server is onboarded.
- Under Options, check Require External ID.
-
Enter the following information:
- External ID - Enter a unique attribute to be used while onboarding AWS S3 in Secure Cloud Access (for example, aws-security-monitor).
- Require MFA - Do not check.
-
Click Next: Permissions.
Do not attach any policies.
- (Optional) Click Next: Tags and enter any tags in the Add Tags page.
- Click Next: Review.
- Enter a Role Name (for example, AWS-Security-Monitor) and click Create Role.
- Search for the role name you created and click it.
- Copy the role ARN.
-
Select Roles > Trust relationships tab > AWS-Security-Monitor summary view.
Locate the Condition section and copy the ExternalID value.