AWS Account(s) Linkage
Focus
Focus
Prisma AIRS

AWS Account(s) Linkage

Table of Contents

AWS Account(s) Linkage

Learn about how to link your AWS account.
Where Can I Use This?What Do I Need?
  • Managed AIRS for AWS
  • Access to Strata Cloud Manager (SCM)
A Managed AIRS for AWS tenant is the central management entity that connects Palo Alto Networks’ Next-Generation Firewall (NGFW) service with your AWS environment. This linkage involves different types of AWS accounts—subscribed, onboarded, and allowlisted—each serving a specific purpose in managing access, billing, and service control.
The Managed AI Runtime security tenant is an instantiation of the Cloud NGFW service platform, refer to AWS Account(s) linkage of Cloud NGFW platform for more details

Types of AWS Account Linkages

FunctionsDescription
Allowlisted AccountsAWS accounts that have explicit access permissions granted to create VPC endpoints for a specific Cloud NGFW resource. These accounts may or may not be previously or subscribed.
Subscribed AccountsAWS accounts that have completed the Managed AIRS for AWS subscription via AWS Marketplace. These accounts are billing-enabled, allowing Managed AIRS for AWS to send metering records to the AWS Marketplace metering service via the billing link established with these account(s).
Onboarded AccountsAWS accounts that are explicitly delegated to Palo Alto Networks using an IAM role. This allows the Cloud NGFW service to access AWS resources in the AWS account for storing logs in CloudWatch log groups or Kinesis Firehose, for accessing decryption certificates in AWS Secrets Manager, for harvesting resource tags, and optionally creating and deleting NGFW endpoints.