General feedback: The documentation should be written to distinctly show configs for IAM User, and configs for IAM Role. Currently, it just lumps both of them together which is confusing and incorrect. We have spotted the error for IAM Role below.
Specific feedback regarding IAM Role:
For IAM Role, it does not go via SPAssumeRolePolicy. That means the documentation needs to show that for IAM Role, you should remove SPAssumeRolePolicy. After we removed it, then it worked. Further info: For IAM Role, it doesn’t connect to child accounts via Management Account. It connects to each account individually. That is why the SPAssumeRolePolicy is irrelevant.
Kindly take note that our feedback is with regards to IAM Role only. We don’t have IAM User in our setup. Hence, that is why we think in general, SailPoint documentation should be written to distinctly show configs for IAM User, and configs for IAM Role. Currently, it is lumped together and IAM Role config documented is incorrect. Hence, this feedback.
Thank you Pam for taking the time to submit feedback on the documenation, appreciate your time and energy improving this for future users! AWS is an important source for us, so having the documenation correct is key for our customer base.
We are also trying to connect to the AWS SaaS connector for ISC and are getting the following error:
openconnector.ConnectorException: [ConnectorException] [Error details] aws_default_error — AWS Client creation failed: Cannot invoke "java.util.Map.get(Object)" because "credentialsMap" is null
Are you able to make the test connection successfully? If yes, could you please guide me on what needs to be done to configure it correctly? I have also dropped you a message. Looking forward to your reply.
Hi Ambuj, Yes we were able to make the test connection successfully and successfully aggregated too. Regarding the “credentialsMap” is null error, we didn’t face this error. Perhaps you can raise it to support.sailpoint.com as they are very quick to reply.
Thanks for the reply, Pamela. Also, when you get a chance, could you please take a look at my previous message in the chat and let me know your thoughts?