Monitoring Amazon AWS

Overview

Add AWS accounts to TOS as devices to monitor and manage your AWS environment. TOS tracks configuration and policy changes across your AWS accounts, giving you ongoing visibility into topology, accurate path analysis, and reliable change automation — along with continuous compliance monitoring.

Supported SDK versions

AWS SDK v1 reached end-of-support in 2025. Therefore, TOS uses AWS SDK v2 by default for all new installations. AWS SDK v1 is supported for upgrades from older versions.

To switch to SDK v2, see Use AWS SDK v2 for AWS monitoring.

In a future TOS version, AWS SDK v2 will become the default both for clean installs and upgrades from previous versions.

All TOS enhancements for AWS added in TOS 5 and later require AWS SDK v2.
AWS onboarding models

TOS supports different models to onboard AWS devices:

  • Single-account onboarding: Add one AWS account at a time using access keys for an IAM user in that account.

  • Cross-account onboarding:  Add multiple AWS accounts using a management account and a single IAM user who assumes a role in each target account.

  • AWS Organizations onboarding: Add member accounts in AWS Organizations through automatic discovery, using a management account, and an IAM user in the management account who assumes an identically-named role in each member account.

AWS and TOS configuration

All onboarding models require configuration in both AWS and TOS:

  • AWS platform configuration: Create the IAM identity and required permissions and required permissions on AWS for the onboarding model you choose.

  • TOS device configuration: Add the AWS account as a device, and provide the required credentials.

    For AWS Organization-based onboarding only, first define and configure the cloud organization in TOS to manage organization-level access.

To see which TOS features are supported for your device, review SecureTrack Features by Vendor.