Prerequisites for Onboarding AWS
Before you onboard your AWS accounts or organizations, review the prerequisites.
Prerequisites for Onboarding AWS
Log in to an AWS account where you can create an IAM role and assign permissions.
Know the account IDs for all AWS accounts you want to onboard. If you're onboarding an organization, make sure to have your organization's root account ID.
You need to specify your account IDs in the onboarding wizard.
If restricting public access to flow logs, configure the ports and IP addresses listed in AWS flow log access IP addresses.
If using AWS Service Control Policies (SCPs), make sure your SCPs don't restrict access to ports or IP addresses in regions required by Illumio.
If onboarding an account instead of an organization, use one onboarding method:
Launch a CloudFormation Stack automatically.
Use an Illumio-provided YAML file as a template to manually create a stack.
Required AWS permissions
Onboarding requires certain permissions. Use the steps described in Onboard an AWS Cloud account and Onboard an AWS Cloud organization to automatically provision the permissions.