Connecting AWS to Osto
This guide walks you through securely connecting your AWS account to Osto for continuous visibility, scanning, and cloud security posture management.
Open the AWS Management Console and sign in with your AWS credentials.
You’ll need to collect a few identifiers and credentials during this setup — follow the steps below carefully.
Find Your AWS Account ID
Your AWS Account ID uniquely identifies your AWS account and is required for integration.
To find it:
In the AWS Console, search for IAM.
Open the IAM (Identity and Access Management) service.

On the IAM Dashboard, locate the AWS Account section.

Copy the Account ID and save it — you’ll need it later.
Assign Permissions to the IAM User
Osto requires read-only access to scan and assess your cloud resources. Assign the following AWS-managed policies:
Under Set permissions, choose Attach policies directly.
Search for and select the following policies:
SecurityAudit
ViewOnlyAccess

Click Next, review details, and then click Create user.
Create Access Keys
Osto authenticates using access keys associated with your IAM user. To create one:
Return to IAM → Users.
Click on the user you created.
Go to the Security credentials tab.
Scroll down to Access keys and click Create access key.

Choose Third-party service (for integrations and monitoring).
Check the confirmation box and click Next.

Fill in the Osto Cloud Connector Form
In the Osto platform, open the Connect a Cloud Provider window and select Amazon Web Services (AWS).
Fill in the fields as follows:
Name: A friendly name for your AWS connection (e.g., “Prod AWS Account”).
Description: Optional description for easier identification.
AWS Account ID: The account ID you copied earlier.
Access Key ID: The Access Key ID from the IAM user you created.
Secret Access Key: The Secret Access Key generated in the previous step.
Once filled, click Connect to authenticate and establish the integration.
Permissions Reference
At minimum, the IAM user must have:
SecurityAuditViewOnlyAccess
If your organization enforces least privilege, you may instead assign a custom IAM role restricted to Osto’s required read-only actions.
Summary of Required Values
AWS Account ID
IAM Dashboard → AWS Account
123456789012
Access Key ID
IAM → Users → Security credentials
AKIAIOSFODNN7EXAMPLE
Secret Access Key
Shown once upon key creation
wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
Troubleshooting (expandable)
Last updated



