Products: Managed Backup (Agent), Managed Backup (Web)
Article ID: m0212Last Modified: 26-Aug-2026

Add an S3 Account Using IAM Role

This chapter covers the following topic: how to add an Amazon S3 account to Managed Backup using IAM roles.

To start backing up your data, you need to specify cloud storage your data will be backed up to. One of the most popular storage providers is AWS S3. You can add an S3 account in Management Console using the following authentication modes:

However, AWS recommends users use IAM roles for security purposes. IAM roles allow flexible custom settings for available features. Thus, for example, you can create a policy for a user that can back up only to S3 or restore image-based backups to EC2.

To add an S3 account using the IAM role, proceed as follows:

  1. Open the Management Console.
  2. Open the Backup > Storage Accounts page.

  1. Click + to launch the Create a new Backup Destination wizard.

  1. On the Storage type step select Amazon S3 & Glacier. Click Next.
  2. On the Storage account step, select an existing storage account or create a new one. By default, existing storage accounts are displayed. To add a new storage account, click Create a new storage account, enter a name, and select Amazon S3 & Glacier or Amazon S3 & Glacier (AWS China).

  1. In the Authentication type select IAM Role (Manual, best practice). Alternatively, select IAM role (MBS wizard) for step-by-step instructions. You can also use Access Key / Secret key (Legacy) option.

  1. The Provider ID will be added automatically. You can click the Copy to clipboard icon to copy the Provider ID.

  2. Enter Role ARN. Refer to the Add Amazon S3 Account via AWS IAM roles for details.

  3. Click Next. Now you can set the backup destination.

  4. On the Storage type step select Amazon S3 & Glacier. Click Next.

  5. On the Storage account step, select an existing storage account or create a new one. By default, existing storage accounts are displayed. To add a new storage account, click Create a new storage account, enter a name, and select Amazon S3 & Glacier or Amazon S3 & Glacier (AWS China).

  1. Specify the bucket. In the Destination display name field, specify the bucket name which will be displayed as a backup destination, then select whether you will use an existing bucket or create a new one:
    • Select the Create New option to create a new bucket. Name the bucket. Select the region to create the new bucket.
    • Select the Select Existing option to use the existing bucket, then select it in the drop-down list. Also you can select an external bucket you have access to.
    • For the buckets with Object Lock turned on, you can enable Default Object Lock features.
    • Enable Object Lock for GFS backups feature. Otherwise this functionality might be permanently disabled. Disable it if this functionality is not needed.

  1. Select the companies or users to assign to the storage account.

Note that it may take a while to assign companies and users to the storage account

  1. Click Next.
  2. View the storage account summary, then click Save.

Added storage account appears in the grid.

  1. Now you can set the backup destination.
https://git.cloudberrylab.com/egor.m/doc-help-mbs.git
Production