Hi Community,
All our S3-connected QuickSight datasets started failing after we accidentally deleted and recreated AWSQuickSightS3Policy outside of QuickSight’s managed flow.
Error:
S3_MANIFEST_ERROR: Access Denied when trying to access manifest file
Already verified:
- QuickSight service role has correct policies
AWSQuickSightS3Policy recreated natively via QuickSight UI
- Bucket policies allow QuickSight service principal and role ARN
- Some datasets now refreshing successfully via CLI
Questions:
- Does deleting/recreating
AWSQuickSightS3Policy cause QuickSight to lose internal authorization for existing data sources?
- Is there a way to force re-authorization of all S3 data sources without recreating them individually?
Thank you!
Hi @Kalyan_reddy
Welcome to the Quick Suite community!
Quick Suite maintains an internal authorization state that is synchronized only when changes are made through its own console (Manage Quick Suite → Security & Permissions → AWS Resources). When the policy is modified or recreated outside of Quick Suite, the service may lose sync with its internal mapping, even though the IAM-level permissions may appear correct.
Best practice: Always manage Quick Suite’s IAM policies through the Quick Suite console rather than directly in IAM. If modifications are made externally, Quick Suite may not be able to recognize or edit the policies, leading to access failures across data sources.
Please refer the following official documentation, which might be helpful for you.
Hi @Kalyan_reddy
It’s been a while since we last heard from you. If you have any further questions, please let us know how we can assist you.
If we don’t hear back within the next 3 business days, we’ll proceed with close/archive this topic.
Thank you!
Hi @Kalyan_reddy
Since we have not heard back from you, I’ll go ahead and close/archive this topic. However, if you have any additional questions, feel free to create a new topic in the community and link this discussion for relevant information.
Thank you!