AmazonSageMakerQueryExecution
This role is used while running a query execution. AWS LakeFormation assumes this role to vend credentials needed by Amazon Athena during query execution.
The AmazonSageMakerQueryExecution role has the AWS policy: SageMakerStudioQueryExecutionRolePolicy attached.
The default AmazonSageMakerQueryExecution
role has the following trust
policy attached:
Important
If you are using your own query execution role (instead of this default
AmazonSageMakerQueryExecution role), then you must modify the permissions of your
provisioning role (whether you're using this default AmazonSageMakerProvisioning-<domainAccountId> role role
or your own custom provisioning role) to include iam:PassRole
and
iam:GetRole
permissions. These permissions enable your provisioning
role to pass the query execution role to AWS LakeFormation during creation of federated
connections. You can include these permissions by attaching the following inline policy to your
provisioning role: