> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Linking target accounts to an AWS service account

> Link AWS target accounts to your service account so CWPP appliances can scan workloads centrally across accounts.

You can link target accounts either when creating new AWS integrations or by updating existing ones.

<Warning>
  The service account can only be linked to a target account that is part of the same AWS organization.
</Warning>

***

## Create new target accounts

### Onboard a single AWS account

<Steps>
  <Step title="On the Plerion dashboard, go to Settings > Integrations">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/settings-integrations-sidenav.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=76e3ee2c20634eb080fc39574d8b029f" alt="Sidebar navigation with Settings expanded and Integrations highlighted" width="655" height="853" data-path="images/integrations/aws/settings-integrations-sidenav.png" />
    </Frame>
  </Step>

  <Step title="Find AWS account and click the + button">
    Click `Add single AWS account` to continue with onboarding a single AWS account.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/add-aws-account.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=9f6c5887de7bee6862a253b74bf23d82" alt="Integrations page with AWS account option and plus button to add integration" width="775" height="491" data-path="images/integrations/aws/add-aws-account.png" />
    </Frame>

    <br />

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/ysQhS5nLnsZHgata/images/integrations/aws/add-aws-account-single-or-multiple.png?fit=max&auto=format&n=ysQhS5nLnsZHgata&q=85&s=a9a11c868122ac4ee567577ff9ad7e8d" alt="Integrations page with AWS account option, with the single account option or multi-account option" width="781" height="484" data-path="images/integrations/aws/add-aws-account-single-or-multiple.png" />
    </Frame>
  </Step>

  <Step title="Select your desired capabilities">
    * Select `CSPM`, `CIEM` and `CWPP`
    * For the CWPP deployment, choose `Service account` and select your service account.
    * Click `Next` to continue.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/create-single-account.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=7b78b78ff80f34e55293e197d813394c" alt="Single-account capabilities with CWPP Service account" width="2364" height="1310" data-path="images/service-account/link/create-single-account.png" />
    </Frame>
  </Step>

  <Step title="Launch the CloudFormation stack">
    Click `Launch stack` to open the **Quick create stack** page in AWS CloudFormation.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/launch-cloudformation-stack-for-aws-service-account.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=cd19accfcdba82f440af9791551b87f4" alt="Launch CloudFormation stack for AWS service account" width="1906" height="580" data-path="images/integrations/aws/launch-cloudformation-stack-for-aws-service-account.png" />
    </Frame>
  </Step>

  <Step title="Verify the Service account parameter and create the stack">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/create-single-account-stack.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=0c0d32101dbee31378509c606a6d5aca" alt="CloudFormation with Service account parameter present" width="2732" height="1190" data-path="images/service-account/link/create-single-account-stack.png" />
    </Frame>
  </Step>

  <Step title="After the stack completes, the AWS integration will be created and linked to your AWS service account." />
</Steps>

***

### Onboard multiple AWS accounts using StackSets

<Steps>
  <Step title="On the Plerion dashboard, go to Settings > Integrations">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/settings-integrations-sidenav.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=76e3ee2c20634eb080fc39574d8b029f" alt="Sidebar navigation with Settings expanded and Integrations highlighted" width="655" height="853" data-path="images/integrations/aws/settings-integrations-sidenav.png" />
    </Frame>
  </Step>

  <Step title="Find AWS account and click the + button">
    Click `Add accounts using Multi-Account Onbooarding` to add mutiple AWS accounts at once.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/add-aws-account.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=9f6c5887de7bee6862a253b74bf23d82" alt="Integrations page with AWS account option and plus button to add integration" width="775" height="491" data-path="images/integrations/aws/add-aws-account.png" />
    </Frame>

    <br />

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/ysQhS5nLnsZHgata/images/integrations/aws/add-aws-account-single-or-multiple.png?fit=max&auto=format&n=ysQhS5nLnsZHgata&q=85&s=a9a11c868122ac4ee567577ff9ad7e8d" alt="Integrations page with AWS account option, with the single account option or multi-account option" width="781" height="484" data-path="images/integrations/aws/add-aws-account-single-or-multiple.png" />
    </Frame>
  </Step>

  <Step title="Select your desired capabilities">
    * Select `CSPM`, `CIEM` and `CWPP`
    * For the CWPP deployment, choose `Service account` and select your service account.
    * Click `Next` to continue.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/create-single-account.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=7b78b78ff80f34e55293e197d813394c" alt="Single-account capabilities with CWPP Service account" width="2364" height="1310" data-path="images/service-account/link/create-single-account.png" />
    </Frame>
  </Step>

  <Step title="Choose Console or CLI and provide the ServiceAccountId">
    * Use the **ServiceAccountId** shown in Plerion.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/create-multi-account-guide-param.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=7dfbf60e2317979ff79a236ca083a24f" alt="ServiceAccountId parameter reference in Plerion guide" width="1968" height="1014" data-path="images/service-account/link/create-multi-account-guide-param.png" />
    </Frame>
  </Step>

  <Step title="If adding more accounts later, use Update Existing StackSet">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/add-aws-updatestackset.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=380040468dcd599f95cb526250f11874" alt="Update Existing StackSet flow in Plerion" width="1977" height="673" data-path="images/integrations/aws/add-aws-updatestackset.png" />
    </Frame>
  </Step>

  <Step title="After the stack completes, the AWS integration will be created and linked to your AWS service account." />
</Steps>

***

## Update existing target accounts

### Update a single AWS account

<Steps>
  <Step title="Open the AWS account you want to update">
    * On the Plerion dashboard, go to `Settings` > `Integrations`, and find the AWS account you want to update
    * Click the edit icon next to **Role ARN**

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/xqwXbDdIvpJS066S/images/integrations/aws/aws-integration-edit-role-arn.png?fit=max&auto=format&n=xqwXbDdIvpJS066S&q=85&s=93681a6d5e3289df29040ad26adad40e" alt="Integrated AWS account with Role ARN highlighted" width="2240" height="1412" data-path="images/integrations/aws/aws-integration-edit-role-arn.png" />
    </Frame>
  </Step>

  <Step title="Enable CWPP and select the service account">
    In the capabilities list, enable CWPP.\
    Under **Deployment strategy**, choose `Service account` and select the service account you created earlier.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/2HBIdIEF_iUoBKh-/images/service-account/link/update-single-account-guide.png?fit=max&auto=format&n=2HBIdIEF_iUoBKh-&q=85&s=dd1615a9ef34233192f9cb13c7cd933d" alt="Select Service account for CWPP in single-account update" width="2054" height="1472" data-path="images/service-account/link/update-single-account-guide.png" />
    </Frame>
  </Step>

  <Step title="Update stack parameters if required">
    If the Plerion template shows updated parameters, modify the stack parameters as shown in the guide.
  </Step>

  <Step title="Run the update in Automated mode (recommended)">
    * Update the stack using the **AWS Console** or **CLI** by following the instructions in Plerion.
    * Automated mode is recommended for simplicity and reliability.
  </Step>

  <Step title="Confirm the integration is updated and linked">
    Once the stack update completes, the AWS account integration will be updated and linked to the service account.
  </Step>
</Steps>

### Update multiple AWS accounts

<Steps>
  <Step title="Open the AWS management account integration">
    * On the Plerion dashboard, go to `Settings` > `Integrations`, and find the AWS management account you want to update
    * Click the edit icon next to **Role ARN**
  </Step>

  <Step title="Select Multi Account Onboarding">
    * In the **Edit integration** page, choose `Update using Multi Account Onboarding`.
    * On the **Select capabilities** screen, enable `CSPM`, `CIEM`, and `CWPP`.
    * Under **Deployment strategy**, select **Service account** and choose the service account you created earlier.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/create-single-account.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=7b78b78ff80f34e55293e197d813394c" alt="Selecting service account for CWPP in multi-account update flow" width="2364" height="1310" data-path="images/service-account/link/create-single-account.png" />
    </Frame>
  </Step>

  <Step title="Open Update Existing StackSet and follow the guide">
    Switch to the **Update Existing StackSet** tab and follow the instructions provided in Plerion.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/2HBIdIEF_iUoBKh-/images/service-account/link/update-multi-account-guide.png?fit=max&auto=format&n=2HBIdIEF_iUoBKh-&q=85&s=bb69cfd65d3018425f05488999f53389" alt="Update Existing StackSet guide in Plerion" width="1602" height="702" data-path="images/service-account/link/update-multi-account-guide.png" />
    </Frame>
  </Step>

  <Step title="Provide the ServiceAccountId parameter">
    When prompted, enter the **ServiceAccountId** shown in the guide.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/2HBIdIEF_iUoBKh-/images/service-account/link/update-multi-account-guide-param.png?fit=max&auto=format&n=2HBIdIEF_iUoBKh-&q=85&s=1835f22aeb9521e8a2241fe986148ec9" alt="ServiceAccountId parameter in update guide" width="1500" height="738" data-path="images/service-account/link/update-multi-account-guide-param.png" />
    </Frame>
  </Step>

  <Step title="Run the update in Automated mode (recommended)">
    * Complete the update using the **AWS Console** or **CLI**, as instructed in Plerion.
    * Automated mode is recommended for simplicity and reliability.
  </Step>

  <Step title="Confirm integrations are updated and linked">
    Once the StackSet finishes, both existing and new AWS account integrations will be updated and linked to the service account.
  </Step>
</Steps>

***

## Verify the link

On the Plerion dashboard, go to `Settings` → `Integrations` and open the AWS account integration.\
The integration will show the linked **Service account**, and CWPP scans will appear once they begin.

<Frame>
  <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/target-account-enabled.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=cbba087c910874ac62e459bfd7dbc3cf" alt="AWS integration page showing linked service account" width="2672" height="896" data-path="images/service-account/link/target-account-enabled.png" />
</Frame>

<br />

<Frame>
  <img src="https://mintcdn.com/pleriondocs/kZep2o9T0iPastk9/images/service-account/link/target-account-scans.png?fit=max&auto=format&n=kZep2o9T0iPastk9&q=85&s=b5cfa393d5e452c00ba9ae4f7d2ca41b" alt="CWPP Asset Scans section showing recent scans" width="2700" height="1194" data-path="images/service-account/link/target-account-scans.png" />
</Frame>

***

## Additional resources created

* **`PlerionApplianceRole` (IAM role in the target account):** Assumed by service account appliances to run scans in the target account.
