Add an AWS service account
Add an AWS service account to store the credential and access information.
Before you begin
You must perform these tasks:
- Set up download jobs for billing and price sheet data for the service account.
- Configure the MID Server for AWS IAM role.
- Role required: sn_clin_core.insights_admin
About this task
A service account is a secure record on your instance that stores the credential and access information for your provider account. Discovery uses the information to access your provider account to get data on each resource in each specified datacenter. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.
Procedure
Navigate to Cloud Cost Management Workspace > Operations > Administration > Service accounts.
Select New.
On the Cloud Service Account form, fill in the fields.
| Field | Description |
|---|---|
| Name | A unique and descriptive name for this service account. |
| Account Id | 12-digit user account number. Expand the list under the AWS account name on the AWS Management Console to view the number.Important: Remove the hyphen characters (-) from the number. |
| Discovery credentials | The credentials needed for ServiceNow applications to access this account. You can configure this field at a later stage, while configuring access to AWS accounts.- If you configured AWS credentials at ServiceNow AI Platform, select the name of the relevant AWS credential. - To use other AWS accounts to access this account, leave the field empty. For example, you don't need to specify the AWS credentials for accounts assuming IAM roles or member accounts using their management account for access. |
| Datacenter URL | URL of the datacenter.This field is required only for AWS GovCloud \(US\) accounts. For example, `https://$service.us-gov-west-1.amazonaws.com/`. |
| Datacenter Type | Type of the datacenter where the account is hosted.Select AWS datacenter. |
| Datacenter discovery status | Status and timestamp of the last execution of Discovery on the datacenter.This value is generated automatically. |
| Is Billing Account | The option for enabling the account to access billing data. |
- Select Save.
Result
The service account that you created gets listed on the Service accounts page.
Related topics
Schedule and manage the jobs that download AWS billing data
Schedule and manage the Cloud Cost Management jobs that download AWS price sheets