📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Connect AWS Account

Connect your Amazon Web Services (AWS) accounts to Lavawall with a read-only role, choose what to monitor, and send the results to your compliance assessments.

Where to find it
Cloud (AWS) › Connect AWS Account
Who can use it
Anyone who can see the page (the "Your MSP AWS Account" section appears only for MSPs)
Plan
AWS Cloud Security Monitoring
For
Everyone

What the page is for

This page connects AWS accounts to Lavawall so they can be checked for threats, risky activity, identity problems, compliance gaps and wasted spend. You create a role in your own AWS account that Lavawall is allowed to use, and a three-step wizard gives you the exact trust policy and permissions to paste.

Each connected account shows its status, when it last synced, the regions being monitored and which data sources are turned on. You can change the data sources, sync on demand or disconnect the account.

The GRC Integration section sends AWS compliance check results to your GRC assessments as automated evidence after each sync, so passing and failing checks update the matching controls.

MSPs can also enter their own AWS account, so that client trust policies point to the MSP rather than to Lavawall directly.

What you see

The Connect AWS Account page (illustration), with the your msp aws account, connected aws accounts, grc integration and connect aws account wizard numbered 1 to 4.
Illustration of the Connect AWS Account page. Numbers match the list below.
  1. Your MSP AWS Account (MSPs only): whether your own AWS credentials are set, with Configure your AWS account or Edit.
  2. Connected AWS Accounts: a card per account with name, account ID, status (Active, Pending or Error), last sync, regions and data sources, and Settings, Sync Now and a disconnect button. Connect AWS Account starts the wizard.
  3. GRC Integration: for each account, the compliance percentage, passing and failing checks, last push time and the linked assessment, with Link Assessment and Push Now, plus Push All to GRC Now and Refresh.
  4. Connect AWS Account wizard: three steps: Create IAM Role, Enter Details and Verify & Connect.

How to connect an AWS account

  1. Click Connect AWS Account.
  2. In Step 1, in the AWS IAM console create a role with trust type Another AWS account. Copy Your unique External ID and the Trust Policy into it.
  3. Attach the AWS managed policies SecurityAudit and ReadOnlyAccess, and add the Inline Cost Policy (use Copy).
  4. Click Next. In Step 2, enter a Friendly name, the 12-digit AWS Account ID and the Role ARN.
  5. Tick the Regions to monitor.
  6. Click Connect Account. Lavawall tests the connection, which can take up to 15 seconds.
  7. When you see Connected!, the first sync is queued. Findings appear within a few minutes.

How to change what is monitored

  1. On the account card, click Settings.
  2. Change the Friendly Name or turn Data Sources on or off: CloudTrail, GuardDuty, IAM, Access Analyzer, Cost Explorer & Trusted Advisor and CIS Benchmark posture & compliance checks.
  3. Click Save Changes.

How to sync or disconnect an account

  1. Click Sync Now on the account card to collect new data straight away.
  2. To disconnect, click the unlink button and confirm. All findings for that account are permanently removed.

How to send AWS results to a GRC assessment

  1. In GRC Integration, click Link Assessment for the account.
  2. Choose an assessment in GRC Assessment, or leave Auto-detect (latest active assessment).
  3. Click Link & Push Now.
  4. Use Push Now for one account or Push All to GRC Now for all of them.

How to set up your MSP AWS account (MSPs)

  1. Click Configure your AWS account.
  2. Choose Credential Type: IAM Access Key or Cross-account Role ARN.
  3. Enter the AWS Account ID and the key or role details.
  4. Click Test & Save. To go back to Lavawall's central account later, click Edit then Remove Credentials.

Tips

  • Tick every region where you run workloads. The Settings dialog does not change regions.
  • AWS Trusted Advisor needs AWS Business or Enterprise Support. Without it, Cost Explorer recommendations still appear.
  • The MSP credentials only need permission to assume roles. They do not need direct access to client accounts.
  • Only assessments that are In Progress, Active or Draft can be linked.
  • Credentials you enter are encrypted.

Troubleshooting

  • "Connection failed." Check the Role ARN, make sure the External ID matches Step 1 exactly, that the trust policy references the right AWS account, and that SecurityAudit and ReadOnlyAccess are attached.
  • "AWS Account ID must be exactly 12 digits." Enter the account number without dashes.
  • "Invalid Role ARN format." The ARN must look like arn:aws:iam::123456789012:role/RoleName.
  • "Select at least one region." Tick at least one region in Step 2.
  • An account card shows Error. Read the message on the card, fix the role in AWS and click Sync Now.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.