Prerequisites
- An AWS account with permission to create IAM policies and, for role-based methods, an assumable IAM role.
- For multi-account discovery, AWS Organizations enabled and the ability to list its accounts.
- Read access to the services you want discovered: Route 53, EC2, Elastic Load Balancing, CloudFront, API Gateway, RDS, and S3. Add
organizations:ListAccountsfor multi-account discovery, andsts:AssumeRolefor role-based methods.
The integration is read-only. It calls only list, describe, and get operations, plus STS and Organizations calls to resolve credentials. It never changes your AWS resources.
Choose a connection method
AWS supports five credential methods. Pick the one that matches how your organization issues AWS access.Connect AWS
1
Open the Applications tab
In the console sidebar, open Integrations and select the Applications tab.
2
Open AWS
Select the AWS card. The connection form opens on the right.
3
Enter a name and choose a connection method
Enter an Integration name, then select a Connection method. The form shows only the fields that method needs.
4
Fill in the credentials
Enter the value for each visible field. Expanded descriptions for every method are below.
5
Choose a region
Enter the AWS region to query — for example,
us-east-1. Optionally add a Regions allow-list to scan more than one region.6
Set a sync schedule (optional)
Turn on Sync schedule and build a cron schedule, or leave it off to sync manually. See Schedule asset syncs.
7
Connect
Select Connect. OASM validates the credentials against AWS before saving the integration.
Access key
Enter the Access Key ID and Secret Access Key. If your credentials are temporary, also enter the Session Token. The integration uses these credentials directly and scans the account they belong to.Assume role (multi-account)
Enter base Access Key ID and Secret Access Key credentials, then the Role ARN and External ID of a role that exists in each account. The integration lists the active accounts in AWS Organizations and assumes that role in each one, in sequence. The base account is checked before any scanning starts. If the base credentials fail, the whole sync fails; if a single member account cannot be assumed, that account is skipped and the rest continue.Cross-account role
Identical to assume role, but without Organizations. Enter base credentials plus the Role ARN and External ID of the role in the single target account.Workload identity
Enter the Role ARN and the Web Identity Token. Use this method when another system issues a short-lived OIDC token.IAM Identity Center (SSO)
The SSO method uses the AWS device-authorization flow, so OASM connects without ever handling your password.1
Enter the region and start URL
Select the IAM Identity Center (SSO) connection method. Enter the AWS region and the SSO Start URL — the address of your access portal, for example
https://your-org.awsapps.com/start.2
Start authorization
Select Start authorization. OASM generates a one-time code and opens the AWS verification page.
3
Approve the request in AWS
Enter the displayed code in the AWS access portal and approve the request. The console polls until AWS confirms it.
4
Select an account and role
Choose the Account ID and Role name the integration should use.
5
Connect
Select Connect. OASM stores the refresh token, encrypted with the workspace key, and completes the integration.
While the console waits for approval, the device code remains valid for a limited time. If it expires, restart the flow from the beginning.
What AWS discovery finds
Discovery runs in two passes: global services once per account, and regional services once per enabled region.
Collections map to target types:
- Domains and hostnames become domain targets.
- Public IP addresses become IP targets.
- VPC and subnet ranges become CIDR targets.
Test and sync
- Test Integration runs a read-only credential check and counts what it would discover. It writes nothing to your inventory.
- Sync now queues a real sync and returns immediately. The detail sheet shows the last run time.
- A scheduled sync uses the same code path as Sync now.
Troubleshooting
Connect fails with a credential error
Connect fails with a credential error
Confirm the region and credentials are correct, and that the identity has the read-only permissions listed above. For role-based methods, verify the role ARN, the external ID, and that the base credentials are allowed to assume the role.
The scheduler rejects my workload identity integration
The scheduler rejects my workload identity integration
Workload identity integrations cannot be scheduled. Turn the schedule off and use Sync now.
Some accounts or regions are missing
Some accounts or regions are missing
Multi-account discovery lists active AWS Organizations accounts, and regional discovery queries the regions you configure. If a sync reports truncation, run it again to continue, or narrow the region allow-list.
The SSO code expired before I approved it
The SSO code expired before I approved it
Restart the connect flow to generate a new code.
Related
Targets
Review the domains and IP ranges AWS discovery adds
Assets
See the assets and services discovered under each target
Integrations overview
Learn how connections, secrets, and schedules work
