> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting started with an AWS account

> Learn how to connect a single Amazon Web Services (AWS) account to Plerion for CSPM, CIEM, and CWPP capabilities.

<Tip>
  For a smoother onboarding experience, log in to your **target AWS account** in the AWS Management Console before starting the setup in Plerion.
</Tip>

## Steps to enable CSPM and CIEM for your AWS account

<Steps>
  <Step title="On the Plerion dashboard, go to Settings > Integrations">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/settings-integrations-sidenav.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=76e3ee2c20634eb080fc39574d8b029f" alt="Sidebar navigation with Settings expanded and Integrations highlighted" width="655" height="853" data-path="images/integrations/aws/settings-integrations-sidenav.png" />
    </Frame>
  </Step>

  <Step title="Find AWS account and click the + button">
    Click `Add single AWS account` to continue with onboarding a single AWS account.\
    Click `Add accounts using Multi-Account Onbooarding` to add mutiple AWS accounts at once.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/add-aws-account.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=9f6c5887de7bee6862a253b74bf23d82" alt="Integrations page with AWS account option and plus button to add integration" width="775" height="491" data-path="images/integrations/aws/add-aws-account.png" />
    </Frame>

    <br />

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/ysQhS5nLnsZHgata/images/integrations/aws/add-aws-account-single-or-multiple.png?fit=max&auto=format&n=ysQhS5nLnsZHgata&q=85&s=a9a11c868122ac4ee567577ff9ad7e8d" alt="Integrations page with AWS account option, with the single account option or multi-account option" width="781" height="484" data-path="images/integrations/aws/add-aws-account-single-or-multiple.png" />
    </Frame>
  </Step>

  <Step title="Select your desired capabilities">
    The CSPM and CIEM capabilities are selected by default.\
    Click `Next` to continue.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/aws-cspm-ciem-selected.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=9ce500bc330efef1d25b3329b986d56e" alt="Capability selection screen showing CSPM and CIEM selected" width="1953" height="1106" data-path="images/integrations/aws/aws-cspm-ciem-selected.png" />
    </Frame>
  </Step>

  <Step title="Choose your setup mode">
    You can grant Plerion access using either **Automated** *(recommended)* or **Manual** mode:
  </Step>
</Steps>

### Automated mode (recommended)

* Click `Launch stack` to open the **Quick create stack** page in AWS CloudFormation.
* Keep the default parameters and acknowledge required capabilities, then click `Create stack`.
* Return to Plerion. While the stack is being created, you’ll see a loader screen.
* Once the stack completes, Plerion will automatically finalize the integration and trigger the first scan.
* The initial scan typically finishes in under 10 minutes for small accounts. You can track progress under `Settings` → `Integrations` → `Scans`, and view results in the **Compliance**, **Well-Architected**, and **Findings** dashboards.

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/automated-mode.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=c0097cf85d2960109c816ff31fea4c23" alt="Plerion page with Automated mode for integrating an AWS account" width="3226" height="1258" data-path="images/integrations/aws/automated-mode.png" />
</Frame>

<br />

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/aws-cloudformation-quick-create-stack-page.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=bbb429931b3558a2c464409fda19a820" alt="AWS CloudFormation Quick create stack page" width="2708" height="1098" data-path="images/integrations/aws/aws-cloudformation-quick-create-stack-page.png" />
</Frame>

<br />

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/cloudformation-default-parameters.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=6c6a0b8c7cd8df876fd1decae0eac499" alt="AWS CloudFormation Quick create stack page with default parameters" width="2646" height="1122" data-path="images/integrations/aws/cloudformation-default-parameters.png" />
</Frame>

<br />

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/plerion-creating-aws-account-integration.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=43e090f86d4ac8452e7a9395974fe7c5" alt="AWS CloudFormation Quick create stack page with default parameters" width="2430" height="1084" data-path="images/integrations/aws/plerion-creating-aws-account-integration.png" />
</Frame>

<br />

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/aws-account-successfully-scanned.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=c22ab8616d769c63d0ec4459a8a68960" alt="AWS CloudFormation Quick create stack page with default parameters" width="1219" height="846" data-path="images/integrations/aws/aws-account-successfully-scanned.png" />
</Frame>

### Manual mode

* Create an IAM role in your target AWS account that trusts Plerion.
* Copy the **Role ARN** and paste it into the **Plerion access role ARN** field, then click `Next`.
* Plerion will verify permissions and start the initial **CSPM/CIEM** scan automatically.
* You can track progress under `Settings` > `Integrations` > `Scans`. When complete, you can view results in **Compliance**, **Well-Architected**, and **Findings**.

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/manual-mode.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=8b2dca954d423de9e77c3d9622fec59b" alt="IAM role creation screen in AWS with trust policy highlighted" width="1872" height="1202" data-path="images/integrations/aws/manual-mode.png" />
</Frame>

<br />

<Frame>
  <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/plerion-access-role-arn.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=82ad7ec49b35fbf8ed03c43c26bc7605" alt="IAM role creation screen in AWS with trust policy highlighted" width="1920" height="612" data-path="images/integrations/aws/plerion-access-role-arn.png" />
</Frame>

***

## Steps to enable CWPP for your AWS account (optional)

To enable CWPP during onboarding, choose one of the following deployment strategies:

* **Plerion-managed scanning** *(recommended)*: Plerion runs the scanning appliances in its own AWS accounts.
  * You only grant a cross-account role. There is no VPC or networking to configure.
  * See [Plerion-managed scanning](/guides/integrations/aws/managed-scanning/overview) for detailed steps.

* **Service account**: Launches Plerion appliances from a dedicated service account.
  * Best option for ongoing customer-hosted workload protection at scale.
  * See [AWS service account setup](/guides/integrations/aws/service-account/getting-started-with-aws-service-account) for detailed steps.

* **Same account**: Launches Plerion appliances directly in the AWS account being onboarded.
  * Requires networking configuration (VPC, Subnet, and Security Groups) to allow appliance traffic.
  * Use the provided CloudFormation template to simplify setup.

<Steps>
  <Step title="Select CWPP while onboarding an AWS account">
    On the **Select capabilities** page, select **Cloud Workload Protection Platform (CWPP)** and click `Next`.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/image12.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=64aaea045b3848d4746ec92a8ad2f78d" alt="CWPP capability selected on AWS Add Integration screen" width="1537" height="771" data-path="images/integrations/aws/image12.png" />
    </Frame>
  </Step>

  <Step title="Choose IAM role creation mode">
    Make sure you are signed in to the target AWS account. Choose either **Automated** (recommended) or **Manual** to create the IAM role that grants Plerion access.
  </Step>

  <Step title="Configure workloads">
    * On the **Workload configuration** page, select which workloads to protect.
    * Supported options are **Amazon Elastic Compute Cloud (EC2)**, **AWS Lambda**, **Amazon Elastic Container Service (ECS)**, **Amazon Elastic Container Registry (ECR)**, **Amazon Machine Images (AMI)**
  </Step>

  <Step title="Configure appliances and networking">
    * On the **Appliance configuration** page, regions containing the selected workloads are displayed. For each region:

      * Provide networking details (VPC, Subnet, and Security Group) that allow outbound access to the internet.
      * Use the `Validate` button to test connectivity.

          <Frame>
            <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/workload-regions.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=5da86f01a36f74750138d76e354b844b" alt="Appliance configuration with workload regions" width="3358" height="1678" data-path="images/integrations/aws/workload-regions.png" />
          </Frame>

          <br />

      You can:

      * **Use the example CloudFormation template** to create the required networking components (VPC, Subnet, Internet Gateway, Route Table, and Network ACL).
      * **Delegate to Plerion**: Use a Plerion-managed template to automatically configure a single region. Multi-region delegation will be supported in a future update, but for now, use [StackSets](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-getting-started-create.html) for multi-region deployments.
  </Step>

  <Step title="Review advanced settings">
    In **Advanced settings**, you can enable additional AWS regions that don’t currently have workloads.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/image16.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=2e2b5ccedad2c19815315cfa367b0eeb" alt="Advanced settings for appliance configuration" width="2310" height="950" data-path="images/integrations/aws/image16.png" />
    </Frame>
  </Step>

  <Step title="Trigger scans and review appliances">
    Each CWPP integration first triggers a CSPM scan, followed by a CWPP scan. For every CWPP scan:

    * An appliance **EC2 instance** is launched in each enabled region.
    * The appliance scans workloads and then terminates automatically.

    You can view workload and appliance details on the **Integration information** page.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/image17.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=d2e46b79614fe63c5264fb2e53b49aad" alt="CWPP scan process" width="1814" height="242" data-path="images/integrations/aws/image17.png" />
    </Frame>

    <br />

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/image18.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=e2f150560a5d55b6f049bde4673676c7" alt="Integration information page showing appliance details" width="1825" height="509" data-path="images/integrations/aws/image18.png" />
    </Frame>
  </Step>
</Steps>

***

### Example CloudFormation template for network configuration

The following is an example CloudFormation template for network configuration. This template can be used to create a VPC, Subnet, Internet Gateway, Route Table, and Network ACL.

Users can create a Stack following [Creating a Stack](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/cfn-console-create-stack.html) or deploy to multiple regions using [StackSets](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-getting-started-create.html).

Copy the following template and save it as a YAML file

```yaml filename="YAML" copy theme={"system"}
AWSTemplateFormatVersion: '2010-09-09'

Parameters:
  CidrBlockParameter:
    Type: String
    Default: '192.168.0.0/24'
    Description: 'CIDR block for Plerion Appliance VPC'

Resources:
  PlerionApplianceVPC:
    Type: AWS::EC2::VPC
    Properties:
      Tags:
        - Key: Owner
          Value: Plerion
        - Key: Purpose
          Value: PlerionCWPPAppliance
      CidrBlock: !Ref CidrBlockParameter
      EnableDnsSupport: true
      EnableDnsHostnames: true

  PlerionApplianceInternetGateway:
    Type: 'AWS::EC2::InternetGateway'
    Properties:
      Tags:
        - Key: Owner
          Value: Plerion
        - Key: Purpose
          Value: PlerionCWPPAppliance

  PlerionApplianceVPCGatewayAttachment:
    Type: 'AWS::EC2::VPCGatewayAttachment'
    Properties:
      InternetGatewayId: !Ref PlerionApplianceInternetGateway
      VpcId: !Ref PlerionApplianceVPC

  PlerionAppliancePublicRouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      Tags:
        - Key: Owner
          Value: Plerion
        - Key: Purpose
          Value: PlerionCWPPAppliance
      VpcId: !Ref PlerionApplianceVPC

  PlerionAppliancePublicRoute:
    DependsOn: PlerionApplianceVPCGatewayAttachment
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PlerionAppliancePublicRouteTable
      DestinationCidrBlock: 0.0.0.0/0
      GatewayId: !Ref PlerionApplianceInternetGateway

  PlerionAppliancePublicSubnet01:
    Type: AWS::EC2::Subnet
    Properties:
      Tags:
        - Key: Owner
          Value: Plerion
        - Key: Purpose
          Value: PlerionCWPPAppliance
      MapPublicIpOnLaunch: true
      CidrBlock: !Ref CidrBlockParameter
      AvailabilityZone: !Select
        - 0
        - Fn::GetAZs: !Ref 'AWS::Region'
      VpcId: !Ref PlerionApplianceVPC

  PlerionAppliancePublicSubnet01RouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      SubnetId: !Ref PlerionAppliancePublicSubnet01
      RouteTableId: !Ref PlerionAppliancePublicRouteTable

  PlerionApplianceNACL:
    Type: AWS::EC2::NetworkAcl
    Properties:
      Tags:
        - Key: Owner
          Value: Plerion
        - Key: Purpose
          Value: PlerionCWPPAppliance
      VpcId: !Ref PlerionApplianceVPC

  PlerionApplianceNACLPublicSubnet01Association:
    Type: AWS::EC2::SubnetNetworkAclAssociation
    Properties:
      NetworkAclId: !Ref PlerionApplianceNACL
      SubnetId: !Ref PlerionAppliancePublicSubnet01

  PlerionApplianceNACLOutbound:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref PlerionApplianceNACL
      RuleNumber: 100
      Protocol: -1
      Egress: true
      RuleAction: allow
      CidrBlock: 0.0.0.0/0

  PlerionApplianceNACLInbound:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref PlerionApplianceNACL
      RuleNumber: 100
      Protocol: -1
      RuleAction: allow
      CidrBlock: 0.0.0.0/0

  PlerionApplianceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      Tags:
        - Key: Owner
          Value: Plerion
        - Key: Purpose
          Value: PlerionCWPPAppliance
      GroupDescription: Allow HTTPS egress
      VpcId: !Ref PlerionApplianceVPC
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 0.0.0.0/0
```
