Home > Amazon > Connect Your Amazon Tenant

    Export to PDF

    Connect Your Amazon Tenant

    To use AvePoint services to manage a tenant in the Amazon platform, the Tenant Owner or Service Administrators must connect the tenant to AvePoint Online Services at first.

    Connecting an Amazon tenant will create policies and an IAM role in the AWS environment of the tenant, which requires an IAM user with at least the following required permissions:

    - iam:CreatePolicy - iam:GetRole - iam:UpdateAssumeRolePolicy - iam:ListPolicyVersions - iam:ListAccountAliases - iam:CreateRole - iam:AttachRolePolicy - iam:UpdateRole - iam:CreatePolicyVersion - iam:DeletePolicyVersion - iam:GetAccountSummary - iam:SetDefaultPolicyVersion

    To connect a tenant, navigate to Management > Tenant management and refer to the instructions below:

    1. On the Tenant management page, click Connect tenant.

    2. The Connect tenant pane appears on the right of the page. Based on the type of tenant that you want to connect, select the Amazon platform.

    3. In the Amazon section, enter Access key ID and Secret access key to specify an IAM user, which will only be used to configure an IAM role and required policies in your AWS environment. For more details on managing your access key ID and secret access key, refer to this .

    4. Click Connect. When you connect an Amazon tenant, AvePoint Online Services will check if your entered access key ID and secret access key are available.

    5. Connecting an Amazon tenant will create an IAM role named AWSTenantAdminRole in the tenant’s AWS environment. Below are the API permissions which will be added to the IAM role:

    APIDescription
    iam:ListAccountAliasesLists the account alias associated with the AWS account.
    iam:GetAccountSummaryRetrieves information about IAM entity usage and IAM quotas in the AWS account.
    1. Once your tenant is successfully connected to AvePoint Online Services, a message prompt will be displayed.