{"id":7,"date":"2016-05-08T12:35:00","date_gmt":"2016-05-08T08:35:00","guid":{"rendered":"http:\/\/yohoho.msp360.com\/?p=7"},"modified":"2024-10-02T13:24:21","modified_gmt":"2024-10-02T09:24:21","slug":"backup-with-iam-users","status":"publish","type":"post","link":"https:\/\/www.msp360.com\/resources\/blog\/backup-with-iam-users\/","title":{"rendered":"MSP360 Backup with AWS IAM Users"},"content":{"rendered":"<div dir=\"ltr\">\n<div style=\"margin-bottom: 10px;\" align=\"left\">\n<p><strong><a href=\"https:\/\/www.msp360.com\/backup\/\" target=\"_blank\" rel=\"noopener noreferrer\">MSP360 Backup<\/a><\/strong> and <strong><a href=\"https:\/\/www.msp360.com\/explorer\/windows\/\" target=\"_blank\" rel=\"noopener noreferrer\">MSP360 Explorer<\/a><\/strong> provide users with an ability to leverage the <strong>Amazon Identity and Access Management (IAM)<\/strong> service that allows you to create multiple users for one AWS account and specify access rights for each user or <a href=\"https:\/\/www.msp360.com\/resources\/blog\/two-step-protection-against-data-breach\/\">the set of users.<\/a><!--more--> Creating an Amazon IAM user with MSP360 ExplorerUse MSP360 Explorer PRO to create AWS IAM user. You can download a <a href=\"https:\/\/www.msp360.com\/download-thanks.aspx?prod=cbes3pro\">fully functional trial version<\/a>, it is free for 15 days.<\/p>\n<p>To start you\u2019ll need an Amazon Web Services account configured in MSP360 Explorer. You can learn how to do that in our <a href=\"http:\/\/www.youtube.com\/watch?feature=player_embedded&amp;v=uwObBqXMOAM\" target=\"_blank\" rel=\"noopener noreferrer\">video tutorial<\/a>.<\/p>\n<div class=\"steps\">\n<p><var>1<\/var>Open MSP360 Explorer PRO, navigate on <strong>Access Man<\/strong><strong>ager (IAM)<\/strong> on the toolbar and select <strong>New Policy Wizard<\/strong>.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28827 size-large\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new-policy-wizard-1024x164.png\" alt=\"New Policy Wizard\" width=\"625\" height=\"100\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new-policy-wizard-1024x164.png 1024w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new-policy-wizard-300x48.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new-policy-wizard-768x123.png 768w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new-policy-wizard-624x100.png 624w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new-policy-wizard.png 1150w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/p>\n<p><var>2<\/var>Select an AWS account you are going to work with.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10771 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_wizard.png\" alt=\"Select an AWS account\" width=\"745\" height=\"522\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_wizard.png 745w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_wizard-300x210.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_wizard-624x437.png 624w\" sizes=\"auto, (max-width: 745px) 100vw, 745px\" \/><\/p>\n<p><var>3<\/var>Create your IAM user and come up with a name for it.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10772 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_iam_user_field.png\" alt=\"Create your IAM user\" width=\"734\" height=\"514\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_iam_user_field.png 734w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_iam_user_field-300x210.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_iam_user_field-624x437.png 624w\" sizes=\"auto, (max-width: 734px) 100vw, 734px\" \/><\/p>\n<p><var>4<\/var>Set up permissions for your IAM user. Just choose an appropriate option. For example, purposes we\u2019ve chosen to grant read and write to selected buckets access to our AWS IAM user. Note: if you don\u2019t want your user to see a list of all of your S3 buckets, uncheck the \u201cAllow the user to access to AWS console\u201d box. It will provide you with a better security level.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10743 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_policy_wizard.png\" alt=\"uncheck the \u201cAllow the user to access to AWS console\u201d box\" width=\"744\" height=\"526\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_policy_wizard.png 744w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_policy_wizard-300x212.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/new_policy_wizard-624x441.png 624w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\" \/><\/p>\n<p><var>5<\/var>Select the buckets to be used in this access policy.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-11332 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/list_of_buckets_script.png\" alt=\"Select the buckets\" width=\"742\" height=\"522\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/list_of_buckets_script.png 742w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/list_of_buckets_script-300x211.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/list_of_buckets_script-624x439.png 624w\" sizes=\"auto, (max-width: 742px) 100vw, 742px\" \/><\/p>\n<p><var>6<\/var>Preview or modify the created access policy script.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10745 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/script_iam.png\" alt=\"access policy script\" width=\"742\" height=\"521\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/script_iam.png 742w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/script_iam-300x211.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/script_iam-624x438.png 624w\" sizes=\"auto, (max-width: 742px) 100vw, 742px\" \/>You can find the full policy script by switching to the <strong>Policy Script <\/strong>tab.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-11328 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/full_policy_script1.png\" alt=\"Policy Script tab\" width=\"741\" height=\"520\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/full_policy_script1.png 741w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/full_policy_script1-300x211.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/full_policy_script1-624x438.png 624w\" sizes=\"auto, (max-width: 741px) 100vw, 741px\" \/> In our example, the script looks like this:<\/p>\n<pre>{ \r\n\r\n    \"Version\":\"2012-10-17\",\r\n    \"Statement\": [\r\n        {\r\n            \"Effect\": \"Allow\",\r\n            \"Action\": [\r\n                \"s3:ListBucket\",\r\n                \"s3:GetBucketAcl\",\r\n                \"s3:GetBucketVersioning\",\r\n                \"s3:GetBucketRequestPayment\",\r\n                \"s3:GetBucketLocation\",\r\n                \"s3:GetBucketPolicy\"  \r\n            ],\r\n            \"Resource\": [\r\n                \"arn:aws:s3:::alex_cloudberry\",\r\n                \"arn:aws:s3:::alextestim\",\r\n                \"arn:aws:s3:::test.cloudberry\"\r\n            ],\r\n            \"Condition\": {}\r\n        },\r\n        {\r\n            \"Effect\": \"Allow\",\r\n            \"Action\": [\r\n                \"s3:GetObject\",\r\n                \"s3:DeleteObject\",\r\n                \"s3:DeleteObjectVersion\",\r\n                \"s3:GetObjectAcl\",\r\n                \"s3:GetObjectVersion\",\r\n                \"s3:GetObjectVersionAcl\",\r\n                \"s3:PutObject\",\r\n                \"s3:PutObjectAcl\",\r\n                \"s3:PutObjectVersionAcl\"\r\n            ],\r\n            \"Resource\": [\r\n                \"arn:aws:s3:::alex_cloudberry\/*\",\r\n                \"arn:aws:s3:::alextestim\/*\",\r\n                \"arn:aws:s3:::test.cloudberry\/*\"\r\n            ],\r\n            \"Condition\": {}\r\n        },\r\n        {\r\n            \"Effect\": \"Allow\",\r\n            \"Action\": \"s3:ListAllMyBuckets\",\r\n            \"Resource\": \"*\",\r\n            \"Condition\": {}\r\n        }\r\n    ]\r\n}<\/pre>\n<p><var>7<\/var>Proceed with the Policy Wizard. After all the steps are completed you'll see the summary window. Now you\u2019ve created your IAM user with limited permissions. To let this new user backup with MSP360 Backup, you need to create <strong>Access and Secret Keys<\/strong> for him. Follow the next instruction of this article to generate access keys!<\/p>\n<\/div>\n<h3 style=\"margin-bottom: 10px;\" align=\"left\"><b>Creating Access Keys<\/b><\/h3>\n<div class=\"steps\">\n<p><var>1<\/var>Open MSP360 Explorer PRO, navigate on <strong>Access Manager (IAM)<\/strong> on the toolbar and select <strong>Access Manager<\/strong>.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10775 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/explorer_manage_iam_manage.png\" alt=\"Access Manager\" width=\"1108\" height=\"194\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/explorer_manage_iam_manage.png 1108w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/explorer_manage_iam_manage-300x53.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/explorer_manage_iam_manage-1024x179.png 1024w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/explorer_manage_iam_manage-624x109.png 624w\" sizes=\"auto, (max-width: 1108px) 100vw, 1108px\" \/><\/p>\n<p><var>2<\/var>Choose your AWS account.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10747 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_user1.png\" alt=\"Choose your AWS account\" width=\"858\" height=\"222\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_user1.png 858w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_user1-300x78.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/select_iam_user1-624x161.png 624w\" sizes=\"auto, (max-width: 858px) 100vw, 858px\" \/><\/p>\n<p><var>3<\/var>Right click on your AWS IAM user and choose <strong>Manage Access Keys<\/strong>.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10748 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/manage_iam_option.png\" alt=\"Manage Access Keys\" width=\"300\" height=\"366\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/manage_iam_option.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/manage_iam_option-246x300.png 246w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><var>4<\/var>In the opened window, click the <strong>Create <\/strong>button. Access Key and Secret Key for your IAM user will be generated automatically.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10776\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/access_key.png\" alt=\"Create button\" width=\"450\" height=\"363\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/access_key.png 418w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/access_key-300x243.png 300w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><a id=\"3\"><\/a><\/p>\n<p><var>5<\/var>\u0421opy your credentials to clipboard or save it to a file.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10777\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/New_Access_Key.png\" alt=\"\u0421opy your credentials\" width=\"455\" height=\"388\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/New_Access_Key.png 447w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/New_Access_Key-300x256.png 300w\" sizes=\"auto, (max-width: 455px) 100vw, 455px\" \/><\/p>\n<\/div>\n<h3 style=\"margin-bottom: 10px;\" align=\"left\"><b>Applying IAM keys to MSP360 Backup<\/b><\/h3>\n<div class=\"steps\">\n<p><var>1<\/var>Launch MSP360 Backup, click on the <strong>Menu Icon<\/strong> in the upper-left corner and click on the <strong>Add New Account <\/strong>button.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28829 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-account-IAM-role.png\" alt=\"Add New Account button\" width=\"499\" height=\"149\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-account-IAM-role.png 499w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-account-IAM-role-300x90.png 300w\" sizes=\"auto, (max-width: 499px) 100vw, 499px\" \/><\/p>\n<p><var>2<\/var>In the \"Select Cloud Storage\" dialog, click on the <strong>Amazon S3<\/strong> icon.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28826 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-S3-IAM-role.png\" alt=\"&quot;Select Cloud Storage&quot; dialog\" width=\"640\" height=\"481\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-S3-IAM-role.png 640w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-S3-IAM-role-300x225.png 300w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/adding-new-S3-IAM-role-624x469.png 624w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p><var>3<\/var>Give your account a name in \"Display Name\" field (you can type any name you want), specify your \"<strong>Access Key \/ Secret Key<\/strong>\" pair and select\u00a0a storage bucket from the \"Bucket name\" drop-down menu.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28828 size-full\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/specifying-account-IAM-role.png\" alt=\"&quot;Access Key \/ Secret Key&quot; pair\" width=\"440\" height=\"567\" srcset=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/specifying-account-IAM-role.png 440w, https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2013\/05\/specifying-account-IAM-role-233x300.png 233w\" sizes=\"auto, (max-width: 440px) 100vw, 440px\" \/><\/p>\n<\/div>\n<p>Now your MSP360 Backup user will have access with configured permissions only to a specified location in your S3 account.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MSP360 Backup and MSP360 Explorer provide users with an ability to leverage the Amazon Identity and Access Management (IAM) service that allows you to create multiple users for one AWS account and specify access rights for each user or the set of users.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[877,894,882],"tags":[],"class_list":["post-7","post","type-post","status-publish","format-standard","hentry","category-blog-articles","category-msp360-backup","category-msp360-news"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/7","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/comments?post=7"}],"version-history":[{"count":2,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/7\/revisions"}],"predecessor-version":[{"id":58696,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/7\/revisions\/58696"}],"wp:attachment":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media?parent=7"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/categories?post=7"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/tags?post=7"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}