External credentials that employ the AWS Signature v4 protocol can now use Amazon’s Roles Anywhere service to secure AWS integrations via certificates. With Roles Anywhere for named credentials, it’s not necessary for AWS administrators to create IAM Users and store their keys in Salesforce.

Where: This change applies to Lightning Experience and Salesforce Classic in all editions.

How: When creating an external credential from the UI, select Roles Anywhere (Assume an IAM Role via Certificate). You can also use the Metadata, Tooling, and Apex ConnectApi APIs to create and edit external credentials.

Use AWS Roles Anywhere with Named Credentials (salesforce.com)

Privacy Preference Center