Create new target accounts
Onboard a single AWS account
Find AWS account and click the + button
Click 

Add single AWS account to continue with onboarding a single AWS account.

Select your desired capabilities
- Select
CSPM,CIEMandCWPP - For the CWPP deployment, choose
Service accountand select your service account. - Click
Nextto continue.

Launch the CloudFormation stack
Click 
Launch stack to open the Quick create stack page in AWS CloudFormation.
Onboard multiple AWS accounts using StackSets
Find AWS account and click the + button
Click 

Add accounts using Multi-Account Onbooarding to add mutiple AWS accounts at once.

Select your desired capabilities
- Select
CSPM,CIEMandCWPP - For the CWPP deployment, choose
Service accountand select your service account. - Click
Nextto continue.

Update existing target accounts
Update a single AWS account
Open the AWS account you want to update
- On the Plerion dashboard, go to
Settings>Integrations, and find the AWS account you want to update - Click the edit icon next to Role ARN

Enable CWPP and select the service account
In the capabilities list, enable CWPP.
Under Deployment strategy, choose
Under Deployment strategy, choose
Service account and select the service account you created earlier.
Update stack parameters if required
If the Plerion template shows updated parameters, modify the stack parameters as shown in the guide.
Run the update in Automated mode (recommended)
- Update the stack using the AWS Console or CLI by following the instructions in Plerion.
- Automated mode is recommended for simplicity and reliability.
Update multiple AWS accounts
Open the AWS management account integration
- On the Plerion dashboard, go to
Settings>Integrations, and find the AWS management account you want to update - Click the edit icon next to Role ARN
Select Multi Account Onboarding
- In the Edit integration page, choose
Update using Multi Account Onboarding. - On the Select capabilities screen, enable
CSPM,CIEM, andCWPP. - Under Deployment strategy, select Service account and choose the service account you created earlier.

Open Update Existing StackSet and follow the guide
Switch to the Update Existing StackSet tab and follow the instructions provided in Plerion.

Provide the ServiceAccountId parameter
When prompted, enter the ServiceAccountId shown in the guide.

Run the update in Automated mode (recommended)
- Complete the update using the AWS Console or CLI, as instructed in Plerion.
- Automated mode is recommended for simplicity and reliability.
Verify the link
On the Plerion dashboard, go toSettings → Integrations and open the AWS account integration.The integration will show the linked Service account, and CWPP scans will appear once they begin.


Additional resources created
PlerionApplianceRole(IAM role in the target account): Assumed by service account appliances to run scans in the target account.



