# Cannot edit \`Desired configuration\` on a device integrated into AWS IoT

**URL:** https://hub.mender.io/t/cannot-edit-desired-configuration-on-a-device-integrated-into-aws-iot/7937
**Category:** General Discussions
**Tags:** aws-iot-core-integration
**Created:** [August 4, 2025, 8:04am UTC](https://hub.mender.io/t/cannot-edit-desired-configuration-on-a-device-integrated-into-aws-iot/7937 "2025-08-04T08:04:06Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![piste-jp](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/piste-jp/32/2544_2.png) [@piste-jp](https://hub.mender.io/u/piste-jp)
#### Post date: [August 4, 2025, 8:04am UTC](https://hub.mender.io/t/cannot-edit-desired-configuration-on-a-device-integrated-into-aws-iot/7937/1 "2025-08-04T08:04:06Z")

</div>

I’m using the mender hosted server and register a device. I found a device entry into AWS IoT core.

But I have a error like this when I try to edit `Desired configuration` from the Mender’s device information.

```auto
There was an error updating the device shadow for device XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX. operation error IoT Data Plane: UpdateThingShadow, https response error StatusCode: 403, RequestID: XXXXXXXX-XXXX-XXXX-XXXX-X... [Request ID: XXXXXX]

```

Now, I attached the permission below to the user of the AWS IoT core.

```auto
                "iot:AttachPolicy",
                "iot:AttachThingPrincipal",
                "iot:CreateCertificateFromCsr",
                "iot:CreatePolicy",
                "iot:CreateThing",
                "iot:DeleteCertificate",
                "iot:DeletePolicy",
                "iot:DeleteThing",
                "iot:DescribeAccountAuditConfiguration",
                "iot:DescribeCertificate",
                "iot:DescribeEndpoint",
                "iot:DescribeThing",
                "iot:DetachThingPrincipal",
                "iot:GetIndexingConfiguration",
                "iot:ListBillingGroups",
                "iot:ListScheduledAudits",
                "iot:ListThingGroups",
                "iot:ListThingGroupsForThing",
                "iot:ListThingPrincipals",
                "iot:ListThingTypes",
                "iot:ListThings",
                "iot:UpdateCertificate",
                "iot:UpdateThingShadow" 

```

Am I missing something?

---

<div class="post-metadata">

### Author: ![piste-jp](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/piste-jp/32/2544_2.png) [@piste-jp](https://hub.mender.io/u/piste-jp)
#### Post date: [August 5, 2025, 8:51am UTC](https://hub.mender.io/t/cannot-edit-desired-configuration-on-a-device-integrated-into-aws-iot/7937/2 "2025-08-05T08:51:49Z")

</div>

I found a solution.

I should set the `iot:UpdateThingShadow` into the policy attach to the IAM user not device policy.

---

<div class="post-metadata">

### Author: ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)
#### Post date: [August 5, 2025, 8:56am UTC](https://hub.mender.io/t/cannot-edit-desired-configuration-on-a-device-integrated-into-aws-iot/7937/3 "2025-08-05T08:56:53Z")

</div>

Hi @piste-jp,

Great, thanks a lot for sharing!

Greetz,  
Josef
