Skip to main content

Updating Existing SaaS Configurations

One-Click Least Privilege. Zero Disruption.



© 2025 Sonrai Security. All rights reserved.

Overview

This guide provides Stack/StackSet update instructions for existing customers with either:

  1. AWS Accounts already onboarded (i.e. existing Stacks/StackSets)

Rather than deleting artifacts in AWS/the Sonrai UI and repeating the entire onboarding process, your SaaS Collector configuration can be more conveniently updated using the steps provided below.

  1. A Delegated Admin Account in use

Remove the firewall entirely, deleting all artifacts in AWS, and repeat the onboarding process with the updated CloudFormation template using the steps provided below.


Updates for Existing Stacks/StackSets

  1. In the left-hand navigation menu, click Manage > Accounts
  1. Click to add a new account.

  2. [AWS UI] - Click on the CloudFormation template link to generate an up-to-date version of the template

  1. [AWS UI] - Copy the CloudFormation template's S3 URL

  1. [AWS UI] - Navigate to Stacks and select your existing "Sonrai-SaaS-Collector-roles"-related stack

  2. [AWS UI] - In the "Stack actions" dropdown menu, click on "Create change set for current stack"

  1. [AWS UI] - Select "Replace current template" and paste in the S3 URL from step 3 above, then click

  1. [AWS UI] - On "Specify stack details" (page 2), set the "Permissions on Demand" option to "Yes", then click

  2. [AWS UI] - Validate your changes, check the "Acknowledge" box and click

  3. [AWS UI] - On "Configure stack options" (page 3), make no changes and click

  4. [AWS UI] - Validate your changes, check the "Acknowledge" box and click

  1. [AWS UI] - Click (and confirm)

  1. [AWS UI] - Once complete, confirm each expected artifact is present:
  • Policy
  • Role
  • StackSet

Updates for Delegated Admin Accounts

Remove the Firewall

  1. Within the Cloud Permissions Firewall, click the settings cog icon menu then the menu option to stage the removal of your current service-related protections in the Pending Changes page.
  1. Deploy the CloudFormation template changes to your AWS Organization.

Reonboard the Firewall

  1. [Sonrai Cloud Permissions Firewall UI] - Navigate to Manage > Accounts

Reference: See here for more information on onboarding AWS Organizations to the firewall.


  1. [Sonrai Cloud Permissions Firewall UI] - Click on the CloudFormation template link to generate an up-to-date version of the template

  1. [AWS UI] - On "Specify stack details" (page 2), input your Delegated Admin account number within the "Enter Delegated Admin account" field:
  1. [AWS UI] - On "Configure stack options" (page 3), make no changes, check the "Acknowledge" box and click

  1. [AWS UI] - Validate your changes and click :
  1. [AWS UI] - Once complete, confirm each expected artifact is present:
  • Policies
  • Roles
  • StackSet