Glue crawler Account is denied access


I'm trying to create a Glue Crawler, but I'm encountering the following error:

"The following crawler failed to create: 'name'. Here is the most recent error message: Account XXXX is denied access."

I've attempted to create it in various regions, but I keep getting the same error.

These are the policies: Policy name

Attached entities AdministratorAccess AmazonEC2FullAccess AmazonS3FullAccess AWSGlueConsoleFullAccess AWSGlueServiceRole AWSLambda_FullAccess CloudWatchEventsFullAccess

And my user has the policy: AdministratorAccess

Error generated by CloudTrail:

"errorCode": "AccessDenied", "errorMessage": "Account xxxx is denied access."

4 Antworten

Hi Bruno, is this account in a orgazination with a SCP attached?

beantwortet vor einem Jahr

Hi there! I got this: FullAWSAccess on AWS Organizations: Service control policies (SCPs)

beantwortet vor einem Jahr

I would check the role policies and permissions...

Check this doc for details: https://docs.aws.amazon.com/glue/latest/dg/security_iam_service-with-iam.html

beantwortet vor einem Jahr

Hello, I appreciate your help!

I did everything that was recommended on the forum and in videos I saw on YouTube, but nothing worked. I also reached out to friends who tried to help me in an online meeting, but without success.

I created a new AWS account, repeated the process from the first attempt, and it worked. So, I have no idea what was happening.

beantwortet vor einem Jahr

