Excel Add-In for Amazon S3

Build 26.0.9770

Minimum IAM Requirements

We recommend using predefined roles for services rather than creating custom IAM policies, but if you want to create custom policies, use the roles described in the following table. Note that the specific policies required by the Amazon S3 driver are subject to change in future releases.

Amazon S3 requires at a minimum the following permissions:

IAM RoleDescription
Tables: Buckets
SELECTListAllMyBuckets
INSERTCreateBucket
DELETEGetBucketLocation and DeleteBucket
Objects
SELECTGetBucketLocation and ListBucket
Views
(All views require GetBucketLocation
in addition to the permission listed below)
BucketACLsGetBucketAcl
BucketAnalyticsGetAnalyticsConfiguration
BucketCORSGetBucketCORS
BucketInventoryGetInventoryConfiguration
BucketLifecycleGetLifecycleConfiguration
BucketReplicationGetReplicationConfiguration
ObjectACLsGetObjectAcl
PublicAccessBlockGetBucketPublicAccessBlock
Stored Procedures
(All procedures require GetBucketLocation
in addition to the permission listed below)
CopyObjectGetObject at the source bucket and PutObject at the destination bucket
MoveObjectGetObject and DeleteObject at the source bucket and PutObject at the destination bucket
DownloadObjectsGetObject
UploadObjectPutObject, and PutObjectAcl when you set an ACL on the upload
CreateBucketCreateBucket
DeleteBucketDeleteBucket
DeleteObjectDeleteObject
PutBucketAclPutBucketAcl
PutObjectAclPutObjectAcl
GetCallerIdentitysts:GetCallerIdentity
GeneratePresignedURLNone. The procedure signs the URL locally; the holder of the URL must have the permission for the operation the URL authorizes.

JSON Example

A JSON version of a minimum permissions policy for full driver functionality is shown in the following code:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:GetBucketPublicAccessBlock",
                "s3:GetLifecycleConfiguration",
                "s3:GetInventoryConfiguration",
                "s3:CreateBucket",
                "s3:ListBucket",
                "s3:GetReplicationConfiguration",
                "s3:PutObject",
                "s3:PutObjectAcl",
                "s3:GetObjectAcl",
                "s3:PutBucketAcl",
                "s3:GetBucketAcl",
                "s3:GetObject",
                "s3:ListAllMyBuckets",
                "s3:GetBucketCORS",
                "s3:GetAnalyticsConfiguration",
                "s3:DeleteObject",
                "s3:GetBucketLocation",
                "s3:DeleteBucket",
                "sts:GetCallerIdentity"
            ],
            "Resource": "*"
        }
    ]
}
In the above example, "Resource" is set to * to allow access to all buckets, but you can limit access to only one specific bucket.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770