---
title: "Amazon Web Services"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1501299231/Amazon%20Web%20Services"
format: markdown
---
There are multiple pre-requisite configuration steps involved in configuring AWS before configuring  Universal Asset Insights in the Infoblox Portal. Failing to follow the pre-requisite configuration stages in AWS will lead to errors. Follow each step shown in the flowchart. You can skip the step that is not applicable to your deployment. For example, if you do not have sub-accounts, you can skip the step.

> ⚠️ Discovery data updates for DNS and IPAM are not supported if your account is configured with only the Infoblox Threat Defense license entitlement.

The following diagram shows various configuration steps. To access detailed information about a specific step, simply click on the corresponding step:

> ⚠️ **Read-only sync:** If you configure read-only sync, you cannot make any changes to AWS DNS objects in the Infoblox Portal.
> ⚠️ 
> ⚠️ **Read/write sync**:  If you configure read/write sync, any changes made to the DNS objects in the Infoblox Portal will be synced to AWS.

![t_AWS_Decision_Final.drawio.png](media://0f13ceee-ab5b-4574-93a6-0f3870e922d9)


> Macro (excerpt)
> 
> > Macro (drawio)


The topics related to each step are available as follows. Perform the steps relevant to your configuration:

1. [Configure AWS for sub-accounts.](https://docs.infoblox.com/space/BloxOneDDI/301826488/AWS+Configuration+for+including+Sub-Accounts)
2. [Apply policy for a single account sync](https://docs.infoblox.com/space/BloxOneDDI/1176863384/IPAM+Sync+Policy+file+for+a+single+account+sync).
3. [Apply policy for multi-account sync](https://docs.infoblox.com/space/BloxOneDDI/971309102/Multi-account+Configuration+in+AWS).
4. [Configure permissions for read-only sync.](https://docs.infoblox.com/space/BloxOneDDI/1176961621/Permissions+required+in+AWS+Route+53+for+Read-only+access)
5. [Configure permissions for read/write sync.](https://docs.infoblox.com/space/BloxOneDDI/1176863337/Permissions+in+AWS+Route+53+for+Bi-directional+Synchronization)
6. [Configure Principal and External ID (recommended).](https://docs.infoblox.com/space/BloxOneDDI/312180908/Configuring+the+Principal+and+External+ID)
7. [Configure Credentials (single account sync only).](https://docs.infoblox.com/space/BloxOneDDI/186616845/Creating+AWS+Credentials)
8. [Configure permissions for Cloud Forwarding.](https://docs.infoblox.com/space/BloxOneDDI/1177092707/Permissions+in+AWS+Route+53+for+Cloud+Forwarding)
9. [Configure permissions for Cloud Forwarder Discovery. ](https://docs.infoblox.com/space/BloxOneDDI/1232897283/Permissions+in+AWS+Route+53+for+Cloud+Forwarder+Discovery)
10. [Configure AWS Managed Policies for Discovery and Asset Inventory.](https://docs.infoblox.com/space/BloxOneDDI/1177059956/AWS+Managed+Policies+for+Discovery+and+Asset+Inventory)


Once you have completed the relevant pre-requisite steps in the diagram, you can proceed to configure Universal Asset Insights for AWS. 

To create a network discovery configuration for Amazon Web Services (AWS), complete the following:

- **Go to Integrations > Discovery > Cloud.**
- Click **Create > AWS**.

> ℹ️ Before configuring discovery for AWS, you must create credentials. For more information, see *[Creating AWS Credentials](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186616845)*.

> ⚠️ When a provider discovery job is deleted in Universal DDI, the DNS zone that was synchronized through that job remains in its original DNS view (for example, *default*), but it is no longer linked to any cloud provider and it will no longer participate in cloud synchronization. If a new discovery job is later created using the same DNS view name, UDDI automatically generates a new provider-linked DNS view (for example, *default-1*) to preserve the integrity of provider associations. To ensure that DNS record updates continue to synchronize with the cloud provider, administrators must add or modify records within the zone that resides under the active provider-linked view (such as *default-1*), rather than in the old, unsynchronized view (*default*).

Configure the following settings in the wizard:

> Macro (children)