> Source: [sk144792](https://support.checkpoint.com/results/sk/sk144792)

# sk144792 - CloudGuard AWS API key is missing permission

| Property | Value |
|----------|-------|
| Solution ID | sk144792 |
| Date Created | 2019-01-16 |
| Last Modified | 2022-07-05 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |

## Symptoms

- AWS API key is missing permission The following article provide information regarding troubleshooting AWS onboarding cloud account error: API key is missing permissions:   

![a1.png](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547633958016/360003623674-a11901160245.png)

## Cause

This error indicates that there may be a permissions problem.  
It can indicate that the AWS IAM Role is missing a mandatory policy, or that the "External ID" is different from the "External ID" given to the AWS IAM Role.

## Solution

**How to resolve this error**

1. Log in to your AWS console ([aws.amazon.com](https://aws.amazon.com/))
2. Click 'Services' and select the IAM service
3. Click 'Roles' and search for the Role created for CloudGuard (usually 'CloudGuard Dome9-Connect' ).
4. On the Role 'permissions' tab verify you have all the **required polices**
   1. **SecurityAudit**(AWS Managed policy) - mandatory policy
   2. '**AmazonInspectorReadOnlyAccess**' (AWS managed policy). - mandatory policy (Required for AWS Inspector information).
   3. **CloudGuard Dome9-readonly-policy** (created for CloudGuard) - mandatory policy  
   4. **CloudGuard Dome9-write-policy** (created for CloudGuard) - (Required for Full protection mode)  
      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547633958016/360003623654-a21901160231.png)  
5. If any of the required polices is not attached, use the attach Policy button in order to attach the missing policies.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547633958016/360003623694-a31901160231.gif)  

6. Verify the External ID on the Role - click 'Trust relationships' tab.
7. Verify the 'External ID' is the same as given on CloudGuard console. (Note - the 'External ID' must not be empty ).  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547633958016/360003638613-a41901160232.png)  

8. If the External ID is empty or needs to be modified click on Edit trust relationship and correct it as required.
9. Copy the Role ARN again to CloudGuard console and the External ID.
10. Click Finish  
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547633958016/360003623634-a51901160232.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
