Sign up for Prowler Updates

Please enable JavaScript in your browser to complete this form.
Toni de la Fuente headshot
Toni de la Fuente // October 31, 2022

Action Required: Update Your ProwlerPro Scan IAM Role

We’ve added new functionality and a new check to ProwlerPro. We also fixed some issues with the existing permissions to improve the way we scan your account, which requires an update to the permissions template.

When you first signed up for ProwlerPro, you created a role in your AWS account with a specific set of locked down permissions. As a security company ourselves, we only have access to what we need for checks to be successful.

In order for all updated checks to continue to work optimally, we are asking all users to update their ProwlerPro scan role. Running this update, with either CloudFormation or Terraform, should take less than 5 minutes.

Recommended Next Steps

Follow these steps to update your CloudFormation template via the AWS CLI as shown below or step by step following the instructions in our documentation here:

aws cloudformation update-stack \
  --capabilities CAPABILITY_IAM --capabilities CAPABILITY_NAMED_IAM \
  --stack-name "ProwlerProSaaSScanRole" \
  --template-url "https://s3.eu-west-1.amazonaws.com/prowler-pro-saas-pro-artifacts/templates/prowler-pro-scan-role.yaml" \
  --parameters "ParameterKey=ExternalId,UsePreviousValue=true"

Follow these steps to to update your ProwlerPro Scan IAM Role via Terraform:

  • Click here to get the latest version of the Terraform files
  • Then execute the following Terraform commands:
terraform init
terraform plan
terraform apply

During the terraform plan and terraform apply steps you will be asked for your AWS External ID which you can find here.

For additional information check out our docs here. If you still have questions, or want to be a part of our community, join us in Slack!

Recent Articles

py iam expand
August 21, 2025

Unmasking Hidden Dangers: How Prowler Now Detects Obfuscated IAM Policies

It all started with a fascinating blog post from the team at Permiso introducing their "Sky Scalpel" tool. Their research highlighted a clever technique for hiding dangerous permissions within AWS...

bedrock header
August 12, 2025

Bedrock’s New API Keys: Convenience at a Hidden Security Cost

Recently, the AWS team rolled out the red carpet for a slick new feature in their post, "Accelerate AI development with Amazon Bedrock API keys." The promise was a dream...

June 24, 2025

CSPM for GCP: Securing Your Google Cloud Environment with Modern Cloud Security Posture Management

Modern organizations rapidly embrace the Google Cloud Platform for its scalability, innovation capabilities, and cost-effectiveness.  However, this digital transformation comes with a critical challenge: maintaining robust security across increasingly complex...