Share a resource discovery with another AWS account
Follow the steps in this section to share a resource discovery using AWS Resource Access Manager. For more information about AWS RAM, see Sharing your AWS resources in the AWS RAM User Guide.
Note
Creating, sharing, and associating resource discoveries is part of the process of integrating IPAM with accounts outside of your organizations (see Integrate IPAM with accounts outside of your organization). If you are not creating an IPAM and integrating it with accounts outside your organization, you do not need to create, share, or associate resource discoveries.
When you create an IPAM that monitors accounts outside your organization, the Secondary Org Admin Account shares their resource discovery with the Primary Org IPAM Account using AWS RAM. You must first share a resource discovery with the Primary Org IPAM Account before the Primary Org IPAM Account can associate the resource discovery with their IPAM. For more information about the roles involved in this process, see Process overview.
Note
When you create a resource share using AWS RAM to share a resource discovery, you must create the resource share in the home Region of the Primary Org IPAM.
The account that creates and deletes a resource share for a resource discovery must have the following permissions in their IAM policy:
ec2:PutResourcePolicy
ec2:DeleteResourcePolicy
If you are integrating an IPAM with accounts outside of your organizations, this is a required step that must be completed by the Secondary Org Admin Account.