AWS Systems Manager Distributor is a tool integrated with AWS Systems Manager that you can use to securely store
and distribute software packages in your accounts. By integrating Workload Security
with AWS Systems Manager Distributor, you can distribute agents across multiple platforms,
control access to managed instances, and automate your deployments.
Create an IAM policy
Follow the instructions in Importing existing managed policies.
In the Import managed policies window, add the AmazonSSMManagedInstanceCore policy.
Create a role and assign the policy
Follow the instructions in Creating a role for an AWS service.
In the Attach permissions policies window, add the AmazonSSMManagedInstanceCore permission.
Create parameters
Procedure
- In your AWS console, navigate to .
- There are four parameters that need to be created. Click Create parameter and enter the Name and Value as listed in the following table. The other fields can be left with their default
values.NameValuedsActivationUrlOn the Workload Security console, go to. Go to the top of the generated script and copy the
dsActivationUrl
.dsManagerUrlOn the Workload Security console, go to. Go to the top of the generated script and copy thedsManagerUrl
.dsTenantIdOn the Workload Security console, go to. Scroll to the bottom of the generated script and copy thetenantID
.dsTokenOn the Workload Security console, go to. Scroll to the bottom of the generated script and copy thetoken
.Make sure the values fordsActivationUrl
anddsManagerUrl
are entered exactly as they appear, taking care to include the trailing slash where applicable.
Create association
Procedure
- In the AWS console, go to .
- Select the TrendMicro-CloudOne-WorkloadSecurity package, then Install on a Schedule.
- The Create Association page opens. Fill in the required fields. For Installation Type, you should use the In-place update option.
- Create a schedule. Using a scheduled State Manager Association ensures that agents are always installed and up to date.
- Click Create Association.
Protect your computers
You should configure a cloud connector for each AWS account which will contain managed agents. It might also be necessary
to create a policy specific to the systems which will be managed by Distributor.