メインコンテンツへスキップ

Permissions

This page lists all the permissions in the managed policy DoiTMspEvidenceReadOnly-v1 that is used to collect AWS evidence for MSP assessment, when connecting AWS accounts to the MSP Workspace.

Backup depth

PermissionDescription
backup:ListBackupPlansLists the active backup plans for the account.
backup:ListBackupVaultsReturns a list of recovery point storage containers along with information about them.
backup:ListBackupJobsReturns a list of existing backup jobs for an authenticated account for the last 30 days.
backup:ListRestoreJobsReturns a list of jobs that AWS Backup initiated to restore a saved resource, including details about the recovery process.

Support plan probe

PermissionDescription
support:DescribeSeverityLevelsReturns the list of severity levels that you can assign to a support case.
support:DescribeTrustedAdvisorChecksReturns information about all available AWS Trusted Advisor checks, including the name, ID, category, description, and metadata.
support:DescribeTrustedAdvisorCheckResultReturns the results of the AWS Trusted Advisor check that has the specified check ID.
support:DescribeTrustedAdvisorCheckSummariesReturns the results for the AWS Trusted Advisor check summaries for the check IDs that you specified.

Well-Architected Tool

PermissionDescription
wellarchitected:ListWorkloadsReturns a paginated list of workloads.
wellarchitected:GetWorkloadRetrieves an existing workload.
wellarchitected:ListAnswersLists answers for a particular workload and lens.

Cost visibility

PermissionDescription
ce:GetCostAndUsageRetrieves cost and usage metrics for your account.
ce:GetRightsizingRecommendationCreates recommendations that help you save cost by identifying idle and underutilized Amazon EC2 instances.
ce:GetSavingsPlansPurchaseRecommendationRetrieves the Savings Plans recommendations for your account.

DevOps Guru

PermissionDescription
devops-guru:DescribeServiceIntegrationReturns the integration status of services that are integrated with DevOps Guru.
devops-guru:ListInsightsReturns a list of insights in your AWS account.

Pipeline history

PermissionDescription
codepipeline:GetPipelineReturns the metadata, structure, stages, and actions of a pipeline.
codepipeline:GetPipelineExecutionReturns information about an execution of a pipeline, including details about artifacts, the pipeline execution ID, and the name, version, and status of the pipeline.
codepipeline:ListPipelinesGets a summary of all of the pipelines associated with your account.
codepipeline:ListPipelineExecutionsGets a summary of the most recent executions for a pipeline.
codebuild:ListProjectsGets a list of build project names, with each build project name representing a single build project.
codebuild:BatchGetProjectsGets information about one or more build projects.
codebuild:ListBuildsGets a list of build IDs, with each build ID representing a single build.
codebuild:ListBuildsForProjectGets a list of build identifiers for the specified build project, with each build identifier representing a single build.
codebuild:BatchGetBuildsGets information about one or more builds.