Skip to main content
The AWS integration discovers internet-facing resources in your AWS account and adds them to your workspace as targets and assets. It connects read-only and runs on a schedule you control.

Prerequisites

  • An AWS account with permission to create IAM policies and, for role-based methods, an assumable IAM role.
  • For multi-account discovery, AWS Organizations enabled and the ability to list its accounts.
  • Read access to the services you want discovered: Route 53, EC2, Elastic Load Balancing, CloudFront, API Gateway, RDS, and S3. Add organizations:ListAccounts for multi-account discovery, and sts:AssumeRole for role-based methods.
The integration is read-only. It calls only list, describe, and get operations, plus STS and Organizations calls to resolve credentials. It never changes your AWS resources.

Choose a connection method

AWS supports five credential methods. Pick the one that matches how your organization issues AWS access.

Connect AWS

1

Open the Applications tab

In the console sidebar, open Integrations and select the Applications tab.
2

Open AWS

Select the AWS card. The connection form opens on the right.
3

Enter a name and choose a connection method

Enter an Integration name, then select a Connection method. The form shows only the fields that method needs.
4

Fill in the credentials

Enter the value for each visible field. Expanded descriptions for every method are below.
5

Choose a region

Enter the AWS region to query — for example, us-east-1. Optionally add a Regions allow-list to scan more than one region.
6

Set a sync schedule (optional)

Turn on Sync schedule and build a cron schedule, or leave it off to sync manually. See Schedule asset syncs.
7

Connect

Select Connect. OASM validates the credentials against AWS before saving the integration.

Access key

Enter the Access Key ID and Secret Access Key. If your credentials are temporary, also enter the Session Token. The integration uses these credentials directly and scans the account they belong to.

Assume role (multi-account)

Enter base Access Key ID and Secret Access Key credentials, then the Role ARN and External ID of a role that exists in each account. The integration lists the active accounts in AWS Organizations and assumes that role in each one, in sequence. The base account is checked before any scanning starts. If the base credentials fail, the whole sync fails; if a single member account cannot be assumed, that account is skipped and the rest continue.

Cross-account role

Identical to assume role, but without Organizations. Enter base credentials plus the Role ARN and External ID of the role in the single target account.

Workload identity

Enter the Role ARN and the Web Identity Token. Use this method when another system issues a short-lived OIDC token.
Workload identity integrations cannot use a sync schedule — the token is short-lived and would be expired on the next run. Leave the schedule off and select Sync now when you want to scan.

IAM Identity Center (SSO)

The SSO method uses the AWS device-authorization flow, so OASM connects without ever handling your password.
1

Enter the region and start URL

Select the IAM Identity Center (SSO) connection method. Enter the AWS region and the SSO Start URL — the address of your access portal, for example https://your-org.awsapps.com/start.
2

Start authorization

Select Start authorization. OASM generates a one-time code and opens the AWS verification page.
3

Approve the request in AWS

Enter the displayed code in the AWS access portal and approve the request. The console polls until AWS confirms it.
4

Select an account and role

Choose the Account ID and Role name the integration should use.
5

Connect

Select Connect. OASM stores the refresh token, encrypted with the workspace key, and completes the integration.
While the console waits for approval, the device code remains valid for a limited time. If it expires, restart the flow from the beginning.

What AWS discovery finds

Discovery runs in two passes: global services once per account, and regional services once per enabled region. Collections map to target types:
  • Domains and hostnames become domain targets.
  • Public IP addresses become IP targets.
  • VPC and subnet ranges become CIDR targets.
Each sync is bounded: at most 50 regions, 20,000 API calls, and 5,000 new targets. A very large account may reach one of these limits, in which case the run is marked truncated and the remainder is picked up on the next sync. Multi-account discovery processes accounts one after another, so a large organization can take several minutes.

Test and sync

  • Test Integration runs a read-only credential check and counts what it would discover. It writes nothing to your inventory.
  • Sync now queues a real sync and returns immediately. The detail sheet shows the last run time.
  • A scheduled sync uses the same code path as Sync now.

Troubleshooting

Confirm the region and credentials are correct, and that the identity has the read-only permissions listed above. For role-based methods, verify the role ARN, the external ID, and that the base credentials are allowed to assume the role.
Workload identity integrations cannot be scheduled. Turn the schedule off and use Sync now.
Multi-account discovery lists active AWS Organizations accounts, and regional discovery queries the regions you configure. If a sync reports truncation, run it again to continue, or narrow the region allow-list.
Restart the connect flow to generate a new code.

Targets

Review the domains and IP ranges AWS discovery adds

Assets

See the assets and services discovered under each target

Integrations overview

Learn how connections, secrets, and schedules work