Skip to main content

Integration errors

The following errors may occur when CWPP is configured for AWS.

AssumeRoleError

User action required: Yes Cause:
This error occurs when the permissions or IAM policies created during AWS CWPP onboarding are missing, invalid, or no longer in effect.
Solution:
Update the affected AWS Account integration(s) by following the appropriate guide:

ServiceAccountDisabled

User action required: Yes Cause:
This error occurs when a CWPP scan runs against a target account whose associated service account is disabled.
Solution:
Re-enable the service account from the Service Account Integration page in the Plerion platform.

NoRegionsEnabled

User action required: Yes Cause:
This error occurs when a CWPP scan is executed under one of the following conditions:
  • In-account integration: No AWS regions were enabled or configured.
  • Target account integration: No AWS regions were enabled or configured for the associated service account.
Solution:

Onboarding issues

The following may occur after an AWS account is onboarded.

Account is not scanned and shows Pending approval

User action required: Yes Cause:
The account belongs to an AWS organization that no other account in your tenant belongs to, so Plerion is holding it for approval. A held account is not scanned on schedule or on demand, and Scan now is disabled. Plerion does not send a notification when this happens, and a held account does not expire.
Solution:
Open the integration under Settings > Integrations and click Approve this account. The account becomes active and its first scan starts immediately. If you do not recognize the account, delete the integration instead of approving it. See Account approval.