IAM permissions - Amazon Elastic Compute Cloud
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

IAM permissions

The IAM role that's attached to your Amazon EC2 Windows instance must have permission to create application-consistent snapshots with VSS. To grant the necessary permissions, you can attach the AWSEC2VssSnapshotPolicy policy to your instance profile.

The policy enables Systems Manager to perform the following actions:

  • Create and tag EBS snapshots

  • Create and tag Amazon Machine Images (AMIs)

  • Attach metadata, such as the device ID, to the default snapshot tags that VSS creates.