Amazon Web Services provider permissions - List of Amazon Web Services (AWS) permissions for use during Cortex Cortex XDR onboarding to enable continuous monitoring in your cloud environment. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide
Abstract

List of Amazon Web Services (AWS) permissions for use during Cortex Cortex XDR onboarding to enable continuous monitoring in your cloud environment.

Notice

Requires a Cortex XDR license that has the Cloud Posture Security or Cloud Runtime Security add-on.

When onboarding Amazon Web Services (AWS), Cortex XDR generates a CloudFormation authentication template that provisions the IAM roles and policies it needs to monitor your cloud environment. This page enumerates every permission that template requests, grouped by security capability.

Important

All conditional capabilities documented below require the mandatory Base and Discovery Engine permissions to be deployed alongside them. Base provides the foundational CortexPlatformRole and AWS-managed read-only baseline. Discovery Engine extends that baseline with the asset-inventory coverage that every other capability assumes.