1. Create a CrossAccount IAM role, with the specific permissions required to protect and recover Amazon EC2 and Amazon EBS, in the specified customer account.
  2. Grant the Rubrik AWS account access to the newly-created role as a trusted entity.
  3. Send the Rubrik AWS account an Amazon Simple Notification Service (SNS) notification about the new role with the role’s Amazon Resource Number (ARN).
  4. Rubrik will create a new IAM user dedicated to the customer account, which Rubrik Polaris will use to assume the new role when needed.