---
title: Granting Access to Your AWS Account for data Inventory
description: Granting Access to Your AWS Account for data Inventory
---

[Skip to content](https://support.block64.com/granting-access-to-your-aws-account-for-data-inventory#main-content)

<https://support.block64.com/kb-tickets/new?hsLang=en> [Customer Portal](https://customerportal.block64.com/tickets-view?hsLang=en)

[![Logo - dark](https://support.block64.com/hs-fs/hubfs/Logo%20-%20dark.png?width=350&height=86&name=Logo%20-%20dark.png)](https://support.block64.com/?hsLang=en)

- [Home](https://support.block64.com/)
- [Insights Portal](https://insights.block64.com/login)
- Platform
  
  Show submenu for Platform

    - [Block 64](https://www.block64.com/)
    - [Why Block 64?](https://www.block64.com/#:~:text=What%20makes%2CBlock%2064%20different)
- Solutions
  
  Show submenu for Solutions

    - [Unified Visibility](https://www.block64.com/solutions/unified-visibility)
    - [Cost Optimization](https://www.block64.com/solutions/cost-optimization)
    - [Proactive Security](https://www.block64.com/solutions/proactive-security)
    - [Compliance](https://www.block64.com/solutions/continuous-compliance)
- Learn
  
  Show submenu for Learn

    - [Quick Start Guides](https://support.block64.com/getting-started)
    - [Integrations](https://support.block64.com/documentation#integrations)
    - [Blog](https://www.block64.com/blog)
- Support
  
  Show submenu for Support

    - [Trust Center](https://trust.block64.com/)
    - [Service Health](https://status.block64.com/)
    - [Partners](https://www.block64.com/partners)
    - [Contact Us](https://www.block64.com/contact)
- [Pricing](https://www.block64.com/pricing)
- [Get Started Free](https://www.block64.com/free-trial)

Open main navigation

Close main navigation

- [Home](https://support.block64.com/)
- [Insights Portal](https://insights.block64.com/login)
- Platform
  
  Show submenu for Platform

    - [Block 64](https://www.block64.com/)
    - [Why Block 64?](https://www.block64.com/#:~:text=What%20makes%2CBlock%2064%20different)
- Solutions
  
  Show submenu for Solutions

    - [Unified Visibility](https://www.block64.com/solutions/unified-visibility)
    - [Cost Optimization](https://www.block64.com/solutions/cost-optimization)
    - [Proactive Security](https://www.block64.com/solutions/proactive-security)
    - [Compliance](https://www.block64.com/solutions/continuous-compliance)
- Learn
  
  Show submenu for Learn

    - [Quick Start Guides](https://support.block64.com/getting-started)
    - [Integrations](https://support.block64.com/documentation#integrations)
    - [Blog](https://www.block64.com/blog)
- Support
  
  Show submenu for Support

    - [Trust Center](https://trust.block64.com/)
    - [Service Health](https://status.block64.com/)
    - [Partners](https://www.block64.com/partners)
    - [Contact Us](https://www.block64.com/contact)
- [Pricing](https://www.block64.com/pricing)
- [Get Started Free](https://www.block64.com/free-trial)
- <https://support.block64.com/kb-tickets/new>
- [Customer Portal](https://customerportal.block64.com/tickets-view)
- [Submit a Support Request](https://support.block64.com/kb-tickets/new)

[Submit a Support Request](https://support.block64.com/kb-tickets/new?hsLang=en)

 How can we assist you today?

- There are no suggestions because the search field is empty.

1. [Block 64 Support Center](https://support.block64.com/?hsLang=en)
2. [Insights Reports](https://support.block64.com/insights-reports?hsLang=en)
3. [The Combine: User Guide](https://support.block64.com/insights-reports?hsLang=en#the-combine-user-guide)

# Granting Access to Your AWS Account for data Inventory

This guide outlines the steps to allow users or roles from **Block 64** (AWS Account ID: `440496705373`) to access your AWS account with read-only permissions across specific AWS services, such as EC2, RDS, Billing, EKS, and AWS pricing.

### **Prerequisites**

- You must have **Admin privileges** in your AWS account.
- You should know the **Block 64 AWS Account ID**: `440496705373`.
- You will be setting up a role with read-only permissions to various AWS services.

---

### **Step-by-Step Instructions**

1. **Login to AWS with Admin Privileges** 
     - Log in to the AWS Management Console using an IAM user or role that has admin-level permissions.
2. **Navigate to the IAM Console**
   
     - From the **AWS Management Console**, search for **IAM** (Identity and Access Management).
     - Open the **IAM** service.
3. **Create a New Role** 
     - In the IAM Console, on the left sidebar, click **Roles** under the **Access Management** section.
     - Click on the **Create role** button.
4. **Specify Trusted Entity** 
     - Under **Select trusted entity**, choose **AWS account**.
     - Select **Another AWS account**.
     - In the **Account ID** field, enter Block 64’s account ID: `440496705373`.
     - Ensure that both **Require external ID** and **Require MFA** options are **not selected**.
     - Click **Next**.
5. **Attach Permissions Policies** 
     - On the **Permissions policies** screen, search for and **select** the following permissions, mapped to the corresponding reports for AWS cloud reports in the app: 
           - `AmazonEC2ReadOnlyAccess`: Grants read-only access to EC2 instances, necessary for the **Virtual Machines** and **Auto Scaling** reports in the app.
           - `AWSBillingReadOnlyAccess`: Allows read-only access to billing information, used for the **Cost Details** report.
           - `AmazonRDSReadOnlyAccess`: Grants read-only access to Amazon RDS databases, required for the **PaaS Databases** report.
           - `AWSPriceListServiceFullAccess`: Grants read-only access to Amazon RDS instance type details like "Vcpu" and "Ram", required for the **PaaS Databases** report.
     - Select all these policies and click **Next**.
6. **Assign Role Name** 
     - In the **Role name** section, provide a descriptive name for the role, such as `Block64ReadOnlyAccess`.
     - Optionally, you can add a description for future reference.
     - Click **Create role**.![](https://support.block64.com/hubfs/Knowledge%20Base%20Import/27252357766423.png)
7. **Add Inline Policy For EKS** 
     - Once the role is created, navigate to the newly created role.
     - Under the **Permissions** tab, click **Add permissions,** then select **Create inline policy**.
     - In the **JSON** tab, paste the following policy, which grants the necessary permissions for the **EKS** report:  
           - ```
             {  "Version": "2012-10-17",  "Statement": [     {        "Sid": "Statement1",        "Effect": "Allow",        "Action": [ "eks:DescribeNodegroup", "eks:ListNodegroups", "eks:DescribeCluster", "eks:ListClusters"        ],        "Resource": "*"    }  ]}
             ```
     - Click **Next**.
     - Give the policy a name (e.g., `EKSReadOnlyInlinePolicy`) and click **Create policy**.
8. **Copy the Role ARN** 
     - On the **Summary** section of the role, locate the **Role ARN** (a string similar to `arn:aws:iam::your-account-id:role/Block64ReadOnlyAccess`)
       
       ![](https://support.block64.com/hubfs/Knowledge%20Base%20Import/27252383278743.png) 
     - Copy the **Role ARN** and share it in Block 64 AWS Manager for inventory credentials.

---

### **Final Notes**

- This role grants Block 64 read-only access to multiple AWS services, including EC2, Billing, RDS, and EKS. You can modify the permissions to add or restrict access to other AWS services as needed.
- The **Role ARN** must be provided to assume the role in your account.

---

### **Troubleshooting**

- If data is not populated on the app, ensure that the **Account ID** in the trusted entity section is correct.
- Verify that all required permissions, including the inline policy for EKS, have been attached to the role.<https://support.block64.com/hc/en-us/search?content_tags=01JJAEKQZE6J850YRVEBFSD510&utf8=%E2%9C%93&hsLang=en>

- [Getting Started](https://support.block64.com/getting-started?hsLang=en#main-content)

    - [Free Trial Onboarding](https://support.block64.com/getting-started?hsLang=en#free-trial-onboarding)
    - [Start Your Subscription](https://support.block64.com/getting-started?hsLang=en#start-your-subscription)
    - [Discovery Application Installation](https://support.block64.com/getting-started?hsLang=en#discovery-application-installation)
    - [Discovery Appliance Setup](https://support.block64.com/getting-started?hsLang=en#discovery-appliance-setup)
    - [Discovery Agent Deployment](https://support.block64.com/getting-started?hsLang=en#discovery-agent-deployment)
- [Insights Reports](https://support.block64.com/insights-reports?hsLang=en#main-content)

    - [IT Asset Management](https://support.block64.com/insights-reports?hsLang=en#it-asset-management)
    - [Security](https://support.block64.com/insights-reports?hsLang=en#security)
    - [Cloud & Infrastructure](https://support.block64.com/insights-reports?hsLang=en#cloud-infrastructure)
    - [The Combine: User Guide](https://support.block64.com/insights-reports?hsLang=en#the-combine-user-guide)
- [Troubleshooting](https://support.block64.com/troubleshooting?hsLang=en#main-content)

    - [Discovery: General Knowledge](https://support.block64.com/troubleshooting?hsLang=en#discovery-general-knowledge)
    - [Discovery: Block 64 Application](https://support.block64.com/troubleshooting?hsLang=en#discovery-block-64-application)
    - [Discovery: BlockBox Appliance](https://support.block64.com/troubleshooting?hsLang=en#discovery-blockbox-appliance)
    - [Discovery: Discovery Agent](https://support.block64.com/troubleshooting?hsLang=en#discovery-discovery-agent)
    - [Insights Calculations](https://support.block64.com/troubleshooting?hsLang=en#insights-calculations)
- [Documentation](https://support.block64.com/documentation?hsLang=en#main-content)

    - [Discovery: General Knowledge](https://support.block64.com/documentation?hsLang=en#discovery-general-knowledge)
    - [Privacy and Security](https://support.block64.com/documentation?hsLang=en#privacy-and-security)
    - [Block 64 API](https://support.block64.com/documentation?hsLang=en#block-64-api)
    - [Integrations](https://support.block64.com/documentation?hsLang=en#integrations)
- [FAQs](https://support.block64.com/faqs?hsLang=en#main-content)

    - [Security](https://support.block64.com/faqs?hsLang=en#security)
    - [Block 64 Discovery](https://support.block64.com/faqs?hsLang=en#block-64-discovery)
- [New Features & Updates](https://support.block64.com/new-features-updates?hsLang=en#main-content)

    - [New Features & Updates](https://support.block64.com/new-features-updates?hsLang=en#new-features-updates)
    - [Combine](https://support.block64.com/new-features-updates?hsLang=en#combine)
    - [Block 64 Discovery](https://support.block64.com/new-features-updates?hsLang=en#block-64-discovery)
    - [Remote Discovery Agent](https://support.block64.com/new-features-updates?hsLang=en#remote-discovery-agent)
    - [Combine API](https://support.block64.com/new-features-updates?hsLang=en#combine-api)
    - [BlockBox Virtual Appliance](https://support.block64.com/new-features-updates?hsLang=en#blockbox-virtual-appliance)

[![Logomark - dark](https://support.block64.com/hs-fs/hubfs/Logomark%20-%20dark.png?width=60&height=96&name=Logomark%20-%20dark.png "Logomark - dark")](http://block64.com)

300 Geary Ave, Toronto, ON M6H 2C5, Canada  
+1 800-875-5260  
[www.block64.com](https://www.block64.com/)

<https://www.linkedin.com/company/block-64/> <https://www.reddit.com/r/Block64/> <https://www.youtube.com/@block64corp> <https://www.block64.com/contact>