> For the complete documentation index, see [llms.txt](https://docs.reveald.com/technical-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.reveald.com/technical-documentation/data-sources-early-access/aws/create-a-new-aws-user-and-aws-api-credentials.md).

# Create a New AWS User and AWS API Credentials

#### Step 1:

* Log into the AWS Management Console using an Admin account.
* In the search field next to the **Services** drop-down menu, type **IAM** and then select the **IAM** service from the drop-down menu.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FZdklK6hdahB4M0rJVvcy%2FPastedGraphic-20.png?alt=media\&token=4f7c89da-c7e5-462d-8acc-823e9f24844a)

#### Step 2:

* In the **IAM** dashboard, under **Access Management** (in the left column), select **Users**. \
  \
  ![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FbnL4ikL6xKrPDN5Shmmy%2FPastedGraphic-21.png?alt=media\&token=33b89d25-5aec-4df4-b0e9-df43f7e3a5e6)
* On the **Users** page, select **Add users** in the upper-right corner.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FwZfnEvOgBiU4ubBLdvdD%2FPastedGraphic-22.png?alt=media\&token=5f7de953-a1d9-43ea-8368-b0cce7264398)

* In the **Add user** pop-up, in **User name*****,*** enter **EIPCollector**.&#x20;
* For **Access type**, select the **Programmatic access** check box.
* Select the **Next: Permissions**.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FMA6AXyBh1uIj6UoanaOr%2FPastedGraphic-23.png?alt=media\&token=8b443cdf-3f97-4fcb-b8db-50f9d7384c87)

### Add Necessary Permission Policies

#### Step 3:

* Under the **Set permissions** drop-down, select **Attach existing policies directly**.&#x20;

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FEKSwVMbRSJDCcABMGqEW%2Fimage.png?alt=media\&token=0faf86b2-1aad-416b-b212-7a0539bee419)

* Select **Create policy** to create a custom policy.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FCRbXrQeeJreuQ6U4dbdO%2Fimage.png?alt=media\&token=9bc0658a-d71e-4667-b72b-85b5dbfd8a7f)

* In the **Create policy** pop-up, on the **Visual editor** tab, for **Service**, select **Network Firewall**, and then select **Read Only Actions**.&#x20;
* For **Resources*****,*** select **Specific** and select the **Any in this account** check-box for **Firewall** and **FirewallPolicy**.&#x20;
* There are no **Request conditions** to complete. Proceed to the next step.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FXxabZJq16AWBEGNAudl4%2FPastedGraphic-24.png?alt=media\&token=4c5d770d-bba2-4fa0-a94f-e0b31423d406)

* No action is needed for the **Add tags** section unless it is necessary for the customer organization. Proceed to the **Review** page.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FVdP6aUQytCL2XLRmIbwz%2FPastedGraphic-25.png?alt=media\&token=98e470c1-28bb-4925-b15e-98e75eba1931)

* Create a **Name** and **Description** for the new policy. A recommended name and description are found in the image below.&#x20;
* Select **Create**.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2F2rLTMfZLVIHFWkTGIDF1%2FPastedGraphic-26.png?alt=media\&token=a1a26620-8bf7-4efc-9be3-3cb3e947b7f8)

#### Step 4:

* In the **Filter policies** search field, type **SecurityAudit** and select **SecurityAudit** from the results. Repeat this procedure for **AmazonVPCReadOnlyAccess**, **AWSNetworkManagerReadOnlyAccess**, and the new custom **NetworkFirewallReadOnly** policies. No **Permission boundary** is needed.&#x20;
* Select **Next: Tags**.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FYTYkVnWpMmIiIYJNUsdF%2FPastedGraphic-31.png?alt=media\&token=ec20fba0-dc01-406b-b538-cc40e127d15b)

* No action is needed for the **Add tags** section unless it is necessary for the customer organization.
* Proceed to the **Review** page.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FTk2kpkBFJkRexDanaVQb%2FPastedGraphic-28.png?alt=media\&token=2715020b-85d2-41ba-a866-24491b767ddb)

* Review the new user and ensure it has the needed traits, as shown in the image below.&#x20;
* Select **Create user**.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FMi0OS8nnX5B5P5l46lTj%2FPastedGraphic-29.png?alt=media\&token=6dedfad3-5dd5-432f-a8b8-eb7dd9df0a3f)

#### Step 5:&#x20;

* At the final stage of creating a new user, a success message displays. Under the success message, the newly generated **Access key ID** and  **Secret access key** appear. Copy them and store them in a secure location.

![](https://4132260347-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ftkp3obVDMu3n9ZTUpfEP%2Fuploads%2FFXJV885KFcn91e4kzaiv%2FPastedGraphic-30.png?alt=media\&token=c9db0328-7f3f-41e5-a1d5-b3ee4be21f1a)

{% hint style="warning" %}
Please note that if you do not copy and store the newly generated credentials they will not be visible later and you will need to create new credentials.
{% endhint %}
