AWS Cloud Account Onboarding
Focus
Focus
Prisma AIRS

AWS Cloud Account Onboarding

Table of Contents

AWS Cloud Account Onboarding

Learn about AWS cloud account onboarding prerequisites and the onboarding workflow in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Prisma AIRS AI Runtime Security in AWS
Onboarding your AWS cloud account connects it to Strata Cloud Manager so Prisma® AIRS™ can discover and protect your AI workloads. Without onboarding, Prisma AIRS cannot see your cloud resources or intercept AI traffic flowing through containers, virtual machines, or serverless functions in your AWS environment.
The onboarding process uses a Terraform template you download from Strata Cloud Manager to create a service account in your AWS environment. The service account grants Prisma AIRS the permissions it needs to read network flow logs, enumerate assets such as EKS clusters, EC2 instances, Lambda functions, and Bedrock models, and—if you choose— orchestrate security VPCs and redirect application traffic through the AI Runtime firewall. AWS Required Permissions lists the specific permissions requested for each function you enable.
Before running the onboarding workflow in Strata Cloud Manager, complete the AWS Cloud Account Onboarding Prerequisites: create an S3 bucket for VPC flow log storage, enable VPC flow logs and Bedrock model invocation logging to that bucket, configure your EKS clusters for IAM-based authentication, and assign IAM roles so your EC2 instances and pods can invoke Bedrock models.
After completing the prerequisites, use Onboard AWS Cloud Account in Strata Cloud Manager to select permission scopes, define application boundaries for asset grouping, download and apply the Terraform template in AWS, and validate asset discovery. Initial discovery data populates in approximately 30 minutes; VPC flow log data may take up to an hour to appear.