When managing access to Amazon S3 buckets through bucket policies, the following error may still occur when attempting to access the bucket, even after allowing the necessary actions and the current IP address ranges of Tableau Cloud.
AccessDenied
User: {user} is not authorized to perform: s3:ListBucket on resource: {resource} because no identity-based policy allows the s3:ListBucket action
If the region of external services accessed via the S3 Connector is the same as the Tableau Cloud Pod region, Tableau Cloud uses Amazon Virtual Private Cloud (Amazon VPC) endpoints to establish a private connection to these external services. In this scenario, customers should use a VPC endpoint instead of relying on IP source addresses to secure the external services shared with Tableau Cloud.
Tableau Cloud Hyperforce Region Name | Pod | VPC Endpoint ID
For Amazon S3 buckets, customers can enable CloudTrail event logging, identify the above Amazon VPC endpoints (vpcEndpointId), and then update the bucket policy to grant the necessary permissions for those VPC endpoints to access the S3 buckets. For more information, please refer to the third-party links below*:
Note: Tableau Cloud also uses VPC endpoint via the Snowflake Connector when the "Protecting internal stages on AWS" setting is enabled in the Snowflake instance. For more details, refer to Snowflake's Protecting internal stages on AWS*.
*Although we make every effort to ensure links to external websites are accurate, up to date, and relevant, Tableau cannot take responsibility for the accuracy or freshness of pages maintained by external providers. Contact the external site for answers to questions regarding its content.
004461877

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.