> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting started with Plerion-managed scanning

> Enable CWPP for an AWS account using Plerion-managed scanning, where Plerion runs the scanning infrastructure in its own accounts and you only grant access

With **Plerion-managed scanning**, you can enable Cloud Workload Protection Platform (CWPP) for an AWS account by granting a single cross-account role. Plerion runs the scanning appliances in its own accounts, so there is no VPC or networking to configure. For background on the model, see the [Plerion-managed scanning overview](/guides/integrations/aws/managed-scanning/overview).

<Tip>
  For a smoother onboarding experience, log in to your **target AWS account** in the AWS Management Console before starting the setup in Plerion.
</Tip>

***

## Steps to enable Plerion-managed scanning

<Steps>
  <Step title="Go to Settings > Integrations">
    On the Plerion dashboard, go to `Settings` > `Integrations`.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/settings-integrations-sidenav.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=76e3ee2c20634eb080fc39574d8b029f" alt="Sidebar navigation with Settings expanded and Integrations highlighted" width="655" height="853" data-path="images/integrations/aws/settings-integrations-sidenav.png" />
    </Frame>
  </Step>

  <Step title="Add a single AWS account">
    Find **AWS account** and click the `+` button, then click `Add single AWS account`.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/add-aws-account.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=9f6c5887de7bee6862a253b74bf23d82" alt="Integrations page with AWS account option and plus button to add an integration" width="775" height="491" data-path="images/integrations/aws/add-aws-account.png" />
    </Frame>
  </Step>

  <Step title="Select capabilities">
    On the **Select capabilities** page:

    * **CSPM** and **CIEM** are required and selected by default. Also select **Cloud workload protection platform (CWPP)**.
    * When CWPP is selected, the **CWPP deployment strategy** section appears with **Plerion-managed service account** already selected as the default and recommended option. Keep it selected.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/select-capabilities-cwpp.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=9ff6807c78b0b6574c9da553e6e3c2b2" alt="Capabilities page with CWPP selected and Plerion-managed service account chosen as the CWPP deployment strategy" width="2000" height="883" data-path="images/integrations/aws/managed-scanning/select-capabilities-cwpp.png" />
    </Frame>
  </Step>

  <Step title="Grant Plerion access">
    Grant Plerion a cross-account role so it can read your AWS account.

    * Click `Launch stack` to open the **Quick create stack** page in AWS CloudFormation.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/automated-mode.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=d0e92e667023119a7946ad1c0ab3d0c6" alt="Grant Plerion access page in Automated mode with the Launch stack button" width="2654" height="1030" data-path="images/integrations/aws/managed-scanning/automated-mode.png" />
    </Frame>

    * Keep the default parameters and acknowledge the required capabilities, then click `Create stack`.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/cloudformation-quick-create-stack.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=80d64d7e1c1be7db92910d4b69b2de51" alt="AWS CloudFormation Quick create stack page" width="1484" height="378" data-path="images/integrations/aws/managed-scanning/cloudformation-quick-create-stack.png" />
    </Frame>

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/cloudformation-default-parameters.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=a6b3dd08a2b1c00c36723af8b1e7652b" alt="AWS CloudFormation Quick create stack page with default parameters and capabilities acknowledged" width="1674" height="1050" data-path="images/integrations/aws/managed-scanning/cloudformation-default-parameters.png" />
    </Frame>

    * Return to Plerion. While the stack is being created, you will see a loader screen. Once it completes, the integration is added.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/plerion-creating-integration.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=55dd387642f180ed57a840f7025037a7" alt="Plerion creating the AWS account integration" width="2152" height="1110" data-path="images/integrations/aws/managed-scanning/plerion-creating-integration.png" />
    </Frame>
  </Step>

  <Step title="Select workload types">
    Under **Workload Types**, select the workloads to scan. The available types are **Amazon EC2 Instance**, **Amazon Machine Image (AMI)**, **AWS Lambda**, **Amazon ECS**, and **Amazon ECR**. All are selected by default.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/select-workloads.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=6bd136c9f03ec56728fa26c85b9157ed" alt="Workload Types section with Amazon EC2, AMI, AWS Lambda, Amazon ECS, and Amazon ECR selected" width="2560" height="740" data-path="images/integrations/aws/managed-scanning/select-workloads.png" />
    </Frame>
  </Step>

  <Step title="Select workload regions">
    Under **Workload regions**, Plerion lists the regions where it detected workloads, along with the **Detected Workload** types in each. Use each region's toggle to set it to **Enabled** or **Disabled**. Use **Advanced Settings** to enable regions that do not currently have detected workloads.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/cLMAiubYY8bvlyDf/images/integrations/aws/managed-scanning/select-regions.png?fit=max&auto=format&n=cLMAiubYY8bvlyDf&q=85&s=2f2cde081be86da41fe7df61c950e38f" alt="Workload regions section with per-region Enabled and Disabled toggles and detected workloads" width="2560" height="820" data-path="images/integrations/aws/managed-scanning/select-regions.png" />
    </Frame>
  </Step>

  <Step title="Review the first scan">
    Plerion triggers the first scan, which runs in Plerion-owned accounts.

    * Track progress under `Settings` > `Integrations` > `Scans`.
    * View results in the **Findings** dashboard once the scan completes.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/image17.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=d2e46b79614fe63c5264fb2e53b49aad" alt="Scans page listing completed CWPP and CSPM scans with status, type, and duration" width="1814" height="242" data-path="images/integrations/aws/image17.png" />
    </Frame>
  </Step>
</Steps>

***

## Resources created in your account

Plerion-managed scanning is enabled through the standard AWS account access stack, which grants Plerion access for CSPM, CIEM, and CWPP.

The CloudFormation stack creates the following resources:

| Resource                          | Resource type           | Description                                                                                                                                                             |
| --------------------------------- | ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| PlerionAccessRole                 | AWS::IAM::Role          | Cross-account role Plerion assumes to read your AWS resource metadata.                                                                                                  |
| PlerionPermissionsBoundary        | AWS::IAM::ManagedPolicy | Permissions boundary that caps the permissions of all Plerion roles and prevents privilege escalation.                                                                  |
| PlerionInstanceProfileRole        | AWS::IAM::Role          | Role granting permission to scan the selected workloads. The Plerion-managed appliances assume this role to read your workloads; only scan results are sent to Plerion. |
| PlerionCSPMAccessPolicy           | AWS::IAM::ManagedPolicy | Read-only permissions Plerion CSPM uses to query your account.                                                                                                          |
| PlerionCSPMDenyPolicy             | AWS::IAM::ManagedPolicy | Explicit denies that bound what Plerion can read.                                                                                                                       |
| PlerionWellArchitectedWritePolicy | AWS::IAM::ManagedPolicy | Write permissions for Plerion to manage Well-Architected workloads.                                                                                                     |
| PlerionAutoUpdateRole             | AWS::IAM::Role          | Role that lets Plerion update only Plerion-managed CloudFormation stacks. See [Auto stack update](/guides/platform/auto-stack-update).                                  |
| PlerionAPILambdaExecutionRole     | AWS::IAM::Role          | Execution role for the onboarding Lambda function.                                                                                                                      |
| PlerionAPICallFunction            | AWS::Lambda::Function   | Lambda function that calls the Plerion API to finalize the integration.                                                                                                 |
| PlerionAPICall                    | Custom::PlerionAPICall  | Custom resource that triggers the onboarding API call.                                                                                                                  |

***

## Next steps

* [Plerion-managed scanning overview](/guides/integrations/aws/managed-scanning/overview)
* [Workload security (CWPP) overview](/guides/platform/cwpp/overview)
