Step 6. Finish Working with Wizard

At the Summary step of the wizard, review summary information and check whether the specified IAM role has all the required permissions — to do that, click Check Permissions. Veeam Backup for AWS will display the Permission check window where you can track the progress and view the results of the performed check. If some permissions of the IAM role are missing, the check will complete with errors, and the list of permissions that must be granted to the IAM role will be displayed in the Missing Permissions column.

You can grant the missing permissions to the IAM role using the AWS Management Console or instruct Veeam Backup for AWS to do it:

  1. In the Permission check window, click Grant.
  2. In the Grant permissions window, provide one-time access keys of an IAM user that is authorized to update permissions of IAM roles, and then click Apply.

The IAM user must have the following permissions:

"iam:AttachRolePolicy",

"iam:CreatePolicy",

"iam:CreatePolicyVersion",

"iam:CreateRole",

"iam:GetAccountSummary",

"iam:GetPolicy",

"iam:GetPolicyVersion",

"iam:GetRole",

"iam:ListAttachedRolePolicies",

"iam:ListPolicyVersions",

"iam:SimulatePrincipalPolicy",

"iam:UpdateAssumeRolePolicy"

Note

Veeam Backup for AWS does not store one-time access keys in the configuration database.

  1. After the required permissions are granted, close the Permission check window, review configuration information and click Finish.

As soon as you click Finish, Veeam Backup for AWS will start adding the backup repository to infrastructure. To track the progress, select the Go to Sessions check box to proceed to the Sessions Log tab.

Checking Permissions for Repository