Skip to main content

How to fix "ASSUME_ROLE" warning from AWS Organization

S
Written by Shannon DeLange
Updated over 2 weeks ago

When using the AWS Organization integration workflow, you might be seeing a warning in the Inventory page, AWS Organization, for certain accounts labeled "ASSUME_ROLE." This indicates that your AWS child account is missing the proper vanta-auditor role required.

Screenshot_2023-01-05_at_12.57.16_PM.png

Procedure

  • Navigate to IAM for the connected AWS management account

  • Locate the role and policy that were created for the vanta integration (role is typically named "vanta-auditor" and policy typically "vantaAdditionalPermissions")

  • The same role needs to be created in the subaccounts with VantaAdditionalPermissions policy as well as the SecurityAudit policy attached

  • Ensure that the trust relationship is set up the same way as well. These IDs will be the same for all of your connected accounts:

TrustRelationshipsvantaauditor.png