This article describes the IAM permissions Flexera uses in AWS. It explains which permissions you can safely remove, when certain permissions are needed, and how Flexera creates and uses IAM policies during cloud onboarding.
This helps you keep your AWS account secure while ensuring Flexera features continue to work as expected.
Permissions you can remove from the Flexera IAM policy
iam:PutRolePolicyFlexera uses this permission only when an instance profile needs to create inline IAM policies. If you don’t rely on this functionality, you can remove it.
iam:CreateServiceLinkedRole
Flexera needs this permission only when creating the first Flexera‑launched instance in your AWS account. After you create an Ocean cluster or Elastigroup and launch at least one instance through Flexera, you can remove this permission.
iam:AddRoleToInstanceProfile
Flexera rarely requires this permission. It’s only needed when updating the role associated with an instance profile, which is typically required for AWS Elastic Beanstalk.
iam:PassRole
Flexera doesn’t need this permission for Ocean on EKS unless you use custom metrics. If you do use custom metrics, you need an account that can publish CloudWatch metric data. Flexera uses this capability for Ocean (PublishOceanKubernetesCwMetricsExecutor) and Elastigroup (ReportCWMetricsNewCmd).
Was this helpful?
Related Articles
Understand differences in EKS node utilization between AWS and the Flexera console 2Number of Views Understanding Flexera One UI session timeout behavior 13Number of Views Understand Flexera Inventory Agent behavior with Apple Virtualization framework 1Number of Views Snow Inventory Java Scanner security levels and execution behavior 143Number of Views Understanding the “Is Deleted” feature in the Flexera Integration app 8Number of Views
Revenera Assistant
Online
Hi, I am Reva - Ask me anything.
Updates
No new updates
Chat
Home
Updates
/**/
Thanks for the feedback!
Your feedback has been saved.Rate this response:
1
2
3
4
5
Add Additional feedback ( Optional )
0/240
English
English
Language changed successfully
Something went wrong
Email sent successfully
Something went wrong
Case create successfully
Are you sure you want to cancel
the case creation?
Please select a product to submit the case.
Please select a product version to submit the case.
0/255
Upload Attachment
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to cancel the case creation?
Case closed successfully
File Upload
Maximum file size allowed is 3 MB.
File type not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Revenera Assistant
© 2026 Flexera Software. All Rights Reserved.
Case id: 00001065
Activity: Status change: 2 hours ago