Integration errors
The following errors may occur when CWPP is configured for AWS.AssumeRoleError
User action required: Yes Cause:This error occurs when the permissions or IAM policies created during AWS CWPP onboarding are missing, invalid, or no longer in effect. Solution:
Update the affected AWS Account integration(s) by following the appropriate guide:
ServiceAccountDisabled
User action required: Yes Cause:This error occurs when a CWPP scan runs against a target account whose associated service account is disabled. Solution:
Re-enable the service account from the Service Account Integration page in the Plerion platform.
NoRegionsEnabled
User action required: Yes Cause:This error occurs when a CWPP scan is executed under one of the following conditions:
- In-account integration: No AWS regions were enabled or configured.
- Target account integration: No AWS regions were enabled or configured for the associated service account.
- For in-account integrations, enable at least one AWS region from the AWS integrations setting page.
- For service account integrations, enable at least one region from the AWS service account settings page.
Onboarding issues
The following may occur after an AWS account is onboarded.Account is not scanned and shows Pending approval
User action required: Yes Cause:The account belongs to an AWS organization that no other account in your tenant belongs to, so Plerion is holding it for approval. A held account is not scanned on schedule or on demand, and
Scan now is disabled. Plerion does not send a notification when this happens, and a held account does not expire.
Solution:Open the integration under
Settings > Integrations and click Approve this account. The account becomes active and its first scan starts immediately. If you do not recognize the account, delete the integration instead of approving it. See Account approval.