Skip to main content

Data import

Connection details

ParameterValue
Base URLhttps://iam.amazonaws.com
Service nameiam
Access KeyEnter your IAM user access key to authenticate your requests.
Secret KeyEnter your IAM user secret key to authenticate your requests.
RegionOptionally, enter the AWS region for the authentication request. For the IAM service, leave the field empty.
Test connectionThis field is optional. You can check this field to force the collector to test the defined connection before moving forward.

Queries and mappings

Users - Accounts

Reference: ListUsers - AWS Identity and Access Management

Parameters:

TabParameterValue
GeneralURL?Action=ListUsers&Version=2010-05-08
GeneralDistinctYes
GeneralEnabledCheck the box
GeneralDescriptionAccounts (ListUsers)
AdvancedHTTP verbGET

Mappings:

DestinationOperatorSource
Business keyMapUserID
Unique IDMapUserName
Acount nameMapUserName
CategoryConstantAccount
Distinguesed nameMapPath

Groups - Resource

Reference: ListGroups

Parameters:

TabParameterValue
GeneralURL?Action=ListGroups&Version=2010-05-08
GeneralEnabledCheck the box
GeneralDescriptionGroups (ListGroups)
DistinctYes
AdvancedHTTP verbGET

Mappings:

DestinationOperatorSource
Business keyMapGroupId
Security resource business keyMapGroupId
NameMapGroupName
CategoryConstantGroup
TypeConstantAWS IAM Group
PathMapPath

Policies - Resource

Reference: ListPolicies

Parameters:

TabParameterValue
GeneralURL?Action=ListPolicies&Version=2010-05-08
GeneralEnabledCheck the box
GeneralDescriptionPolicies (ListPolicies)
DistinctYes
AdvancedHTTP verbGET

Mappings:

DestinationOperatorSource
Business keyMapPolicyId
Security resource business keyMapPolicyId
NameMapPolicyName
CategoryConstantResource
TypeConstantAWS IAM Policy
Short nameMapArn
PathMapPath

Account and Group Assignment – Resource Assignment

Reference: GetAccountAuthorizationDetails

Parameters:

TabParameterValue
GeneralURL?Action=GetAccountAuthorizationDetails&Version=2010-05-08&Filter.member.1=User
GeneralCollectionUserDetailList
GeneralEnabledCheck the box
GeneralDistinctYes
GeneralDescriptionAccount -> Group assignment (GetAccountAuthorizationDetails)
AdvancedHTTP verbGET

Mappings:

DestinationOperatorSource
Resource Business keyLookupName=GroupList
Account - business keyMapUserId
Account is groupConstantFalse

Account and Policy Assignment – Resource Assignment

Reference: GetAccountAuthorizationDetails

Parameters:

TabParameterValue
GeneralURL?Action=GetAccountAuthorizationDetails&Version=2010-05-08&Filter.member.1=User
GeneralCollectionUserDetailList
GeneralEnabledCheck the box
GeneralDistinctYes
DescriptionAccount -> Policy assignment (GetAccountAuthorizationDetails)
AdvancedHTTP verbGET

Mappings:

DestinationOperatorSource
Resource Business keyLookupName=AttachedManagedPolicies_PolicyName
Account - business keyMapUserId
Account is groupConstantFalse

Group and Policy Assignment – Resource Assignment

Reference: GetAccountAuthorizationDetails

Parameters:

TabParameterValue
GeneralURL?Action=GetAccountAuthorizationDetails&Version=2010-05-08&Filter.member.1=Group
GeneralCollectionGroupDetailList
GeneralEnabledCheck the box
GeneralDistinctYes
DescriptionGroup -> Policy assignment (GetAccountAuthorizationDetails)
AdvancedHTTP verbGET

Mappings:

DestinationOperatorSource
Resource Business keyLookupName=AttachedManagedPolicies_PolicyName
Account - business keyMapUserId
Account is groupConstantFalse

Account rules

The Omada AWS connectivity has the following account rules. You can adjust them to meet the requirements of your setup.

Ownership rule

The account owner is set to the identity where the Identity's unique ID value of the identity matches the Account UID value of the account.

FieldValue
TypeIdentity lookup
Join reasonExact Match
Account attributeAccount UID
Identity attributeIdentity’s unique ID

Classification rule

If an account with the account attribute Identity join reason equals Exact Match, the account type is set to Personal.

FieldValue
Account typePersonal
Scope attributeIdentity join reason
Scope operatorEquals
Scope valueExact Match