---
name: satellite-iam-common
title: Common permissions in other cloud providers
description: Review commonly required permissions for creating and managing Satellite infrastructure in cloud providers.
last-updated: 2026-08-28
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/satellite?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Common permissions in other cloud providers
{: #iam-common}

Review commonly required permissions for creating and managing Satellite infrastructure in cloud providers.
{: shortdesc}



## AWS permissions
{: #permissions-aws}

When you use an [IBM Cloud&reg; Schematics template](https://cloud.ibm.com/docs/satellite?topic=satellite-loc-aws-create-auto&format=markdown) to create your Satellite location, you must be assigned a role that can create virtual instances and networks in AWS. For example, you can be assigned the [**AmazonEC2FullAccess** built-in role](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonEC2FullAccess.html){: external} in AWS. For more information about other built-in roles, see the [AWS documentation](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/policy-list.html){: external}.

## Azure permissions
{: #permissions-azure}

When you use an [IBM Cloud&reg; Schematics template](https://cloud.ibm.com/docs/satellite?topic=satellite-loc-azure-create-auto&format=markdown) to create your Satellite location, you must be assigned a role that can create virtual instances and networks in Microsoft Azure. For example, you can be assigned the [**Contributor** built-in role](https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#contributor){: external} in Azure. For more information about other built-in roles, see the [Azure documentation](https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles){: external}.


## Google Cloud Platform permissions
{: #permissions-gcp}

When you use an [IBM Cloud&reg; Schematics template](https://cloud.ibm.com/docs/satellite?topic=satellite-loc-gcp-create-auto&format=markdown) to create your Satellite location, you must be assigned a role that can create virtual instances and networks in Google Cloud Platform. For example, you can be assigned the [**Cloud Build Editor**](https://docs.cloud.google.com/iam/docs/roles-permissions#cloudbuild.builds.editor){: external} role in a specific project in GCP IAM. For more information about role permissions in GCP, see the [GCP documentation](https://docs.cloud.google.com/iam/docs/roles-permissions){: external}.




## VMware permissions
{: #permissions-vmware}

Assign the **Administrator** role for VMware vSphere vCenter servers when using a [IBM Cloud&reg; Schematics template](https://cloud.ibm.com/docs/satellite?topic=satellite-loc-vmware-create-auto&format=markdown). See the [VMware documentation](https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/vsphere-security.html){: external}.
{: shortdesc}