AWS IAM Policies for Protecting Amazon EC2 and Amazon VPC with Commvault

To protect Amazon EC2 and Amazon VPC resources, the Commvault software requires access to your AWS account using AWS Identity and Access Management (IAM) policies that are associated with IAM roles or users. The policies must have the permissions that are necessary for Commvault to perform data protection operations.

Considerations and Recommendations

  • Commvault protects AWS environments that use AWS Organizations, AWS Control Tower, and Service Control Policies (SCPs).

  • The permissions that are required depends on the operations that you need to perform. To restrict operations, remove individual permissions from the IAM policy.

  • Use tags or TagKeys to further restrict the scope of access for Commvault data protection operations.

  • When using resources from an admin account, you must add JSON permissions to both admin and tenant accounts.

  • When implementing the IAM policies, validate their operation using IAM Access Analyzer and the steps in Troubleshooting AWS Organizations policies. When implementing changes to IAM policies in environments that are governed using SCPs, run backup and recovery tests to verify that the results are as expected.

Policies for Amazon EC2

Backups and Restores

Backups to an Amazon S3 Library

Agentless File Recovery

Policies for Amazon EC2 with Database, File System, or Application Agents

Policies for Amazon VPC

Backups

Backups to an Amazon S3 Library

Restores

Agentless File Recovery

×

Loading...