IAM (Identity and Access Management) is an AWS feature you can use to control who is authenticated and authorized to use resources. To deploy Deep Discovery Inspector, ensure your IAM user has the following permissions.
AWS service
Policy name
EC2 instances
  • AmazonEC2FullAccess
  • IAMReadOnlyAccess
  • AllowAssumeCIEC2Deployment
  • AmazonEC2SpotFleetTaggingRole
EC2 Network & Security
  • AmazonEC2FullAccess
  • IAMReadOnlyAccess
  • AllowAssumeCIEC2Deployment
  • AmazonEC2SpotFleetTaggingRole
EC2 Load Balancing
  • AmazonEC2FullAccess
  • IAMReadOnlyAccess
  • AllowAssumeCIEC2Deployment
  • AmazonEC2SpotFleetTaggingRole
VPC TRAFFIC MIRRORING
  • AmazonEC2FullAccess
  • IAMReadOnlyAccess
  • AllowAssumeCIEC2Deployment
  • AmazonEC2SpotFleetTaggingRole
AWS Marketplace
AWSMarketplaceManageSubscriptions
AWS Compute Optimizer finding
ComputeOptimizerReadOnlyAccess