> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# SageMaker Notebook Instance Missing Active Execution Roles

### More Info:

SageMaker Notebook Instance is missing active execution roles

### Risk Level

High

### Address

Security

### Compliance Standards

* APRA CPS 234 (Australia)
* BSI C5 (Germany)
* Brazil LGPD
* CCPA / CPRA (California)
* CIS Critical Security Controls v8
* CMMC 2.0
* CSA Cloud Controls Matrix v4
* DPDPA
* Digital Operational Resilience Act (EU)
* ISO/IEC 27018
* ISO/IEC 27701
* MAS Technology Risk Management (Singapore)
* MITRE ATT\&CK (Cloud)
* NIST SP 800-171
* NYDFS 23 NYCRR 500
* SOC2
* SWIFT Customer Security Controls Framework
* Sarbanes-Oxley IT General Controls
* UK NCSC Cyber Assessment Framework

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Using Console" defaultOpen="true">
        To remediate “SageMaker Notebook Instance Missing Active Execution Roles” using the AWS Management Console, you either attach an existing IAM role or create/attach a new one.

        ### 1. Identify the affected Notebook Instance

        1. Sign in to the **AWS Management Console**.
        2. Go to **Amazon SageMaker**.
        3. In the left pane, select **Notebook instances**.
        4. Find the notebook instance that has the missing execution role issue.

        ***

        ### 2. Check if a role is currently associated

        1. Click the **name** of the notebook instance.
        2. In the **Details** section, look for **IAM role**:
           * If it says “None” or the role is not valid, you must assign a new/existing role.

        > Note: If the notebook is **InService**, you must stop it before changing the role.

        ***

        ### 3. Stop the notebook instance (if running)

        1. On the notebook instance details page, choose **Stop**.
        2. Wait until the **Status** changes to **Stopped**.

        ***

        ### 4A. Option 1 – Attach an existing IAM role

        Use this if you already have a valid SageMaker execution role.

        1. In the notebook instance details page, choose **Edit** (or **Edit notebook instance**).
        2. Under **Permissions and encryption** (or **IAM role** section):
           * For **IAM role**, select **Use an existing role**.
           * From the dropdown, choose a valid SageMaker execution role (for example, `AmazonSageMaker-ExecutionRole-...`).
        3. Choose **Save changes** (or **Update notebook instance**).
        4. After the update is complete, choose **Start** to restart the notebook instance.

        ***

        ### 4B. Option 2 – Create a new IAM execution role and attach it

        Use this if no suitable role exists.

        1. In the same **Edit notebook instance** screen:
           * For **IAM role**, select **Create a new role**.
        2. A dialog appears:
           * For **S3 buckets you specify**:
             * Choose **Any S3 bucket** (broad access) or
             * **Specific S3 buckets** (more secure), and list the bucket(s) you need.
           * Click **Create role**.
        3. SageMaker will create an IAM role (e.g., `AmazonSageMaker-ExecutionRole-YYYYMMDDTHHMMSS`).
        4. Ensure that role is selected in the **IAM role** dropdown.
        5. Choose **Save changes** (or **Update notebook instance**).
        6. After the update, choose **Start** to restart the notebook instance.

        ***

        ### 5. (Optional) Refine the IAM role permissions

        If you need to further restrict permissions:

        1. In the AWS console, go to **IAM** > **Roles**.
        2. Search for and select the role attached to the notebook instance.
        3. Under **Permissions**, adjust the attached policies:
           * Ensure at minimum a SageMaker execution policy (e.g., `AmazonSageMakerFullAccess` or a custom, least-privilege policy for your use case).
           * Ensure required S3, CloudWatch Logs, and other service permissions as needed.

        ***

        After these steps, the notebook instance will have an active execution role, resolving the “Missing Active Execution Roles” misconfiguration.
      </Accordion>

      <Accordion title="Using CLI">
        To remediate “SageMaker Notebook Instance Missing Active Execution Roles” using AWS CLI, you need to (1) ensure a valid IAM role exists, (2) attach appropriate policies, and (3) associate the role with the notebook instance.

        Below is a concise step‑by‑step:

        ***

        ### 1. Identify the Notebook Instance and Its Role

        ```bash theme={null}
        aws sagemaker list-notebook-instances
        ```

        Pick the `NotebookInstanceName` you care about, then:

        ```bash theme={null}
        aws sagemaker describe-notebook-instance \
          --notebook-instance-name <NOTEBOOK_NAME>
        ```

        Check the `RoleArn` field:

        * If it’s missing or empty → you must create and attach a role.
        * If present but the role is deleted/disabled/misconfigured → fix that role or create a new one, then reattach.

        ***

        ### 2. Create an IAM Role for SageMaker (if you don’t have one)

        **2.1 Create the trust policy JSON (trust-sagemaker.json)**

        ```json theme={null}
        {
          "Version": "2012-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Principal": {
                "Service": "sagemaker.amazonaws.com"
              },
              "Action": "sts:AssumeRole"
            }
          ]
        }
        ```

        Save as `trust-sagemaker.json`, then run:

        ```bash theme={null}
        aws iam create-role \
          --role-name SageMakerExecutionRole \
          --assume-role-policy-document file://trust-sagemaker.json
        ```

        Note the returned `Arn`, e.g. `arn:aws:iam::<ACCOUNT_ID>:role/SageMakerExecutionRole`.

        ***

        ### 3. Attach Required Policies to the Role

        Minimum: access to SageMaker and any data sources (S3, etc.). As a quick fix, you can attach AWS-managed policies (adjust to your security requirements later):

        ```bash theme={null}
        aws iam attach-role-policy \
          --role-name SageMakerExecutionRole \
          --policy-arn arn:aws:iam::aws:policy/AmazonSageMakerFullAccess
        ```

        Common additions (optional; tighten as needed):

        ```bash theme={null}
        aws iam attach-role-policy \
          --role-name SageMakerExecutionRole \
          --policy-arn arn:aws:iam::aws:policy/AmazonS3FullAccess
        ```

        (Prefer custom least‑privilege policies in production.)

        ***

        ### 4. Stop the Notebook Instance (required before updating role)

        ```bash theme={null}
        aws sagemaker stop-notebook-instance \
          --notebook-instance-name <NOTEBOOK_NAME>
        ```

        Wait until it’s `Stopped`:

        ```bash theme={null}
        aws sagemaker describe-notebook-instance \
          --notebook-instance-name <NOTEBOOK_NAME> \
          --query 'NotebookInstanceStatus'
        ```

        Repeat until it returns `"Stopped"`.

        ***

        ### 5. Attach/Update the Execution Role on the Notebook

        Use the role ARN from step 2:

        ```bash theme={null}
        aws sagemaker update-notebook-instance \
          --notebook-instance-name <NOTEBOOK_NAME> \
          --role-arn arn:aws:iam::<ACCOUNT_ID>:role/SageMakerExecutionRole
        ```

        ***

        ### 6. Restart the Notebook Instance

        ```bash theme={null}
        aws sagemaker start-notebook-instance \
          --notebook-instance-name <NOTEBOOK_NAME>
        ```

        Optionally verify:

        ```bash theme={null}
        aws sagemaker describe-notebook-instance \
          --notebook-instance-name <NOTEBOOK_NAME> \
          --query '[NotebookInstanceStatus, RoleArn]'
        ```

        You should see `["InService", "arn:aws:iam::<ACCOUNT_ID>:role/SageMakerExecutionRole"]`.

        ***

        This clears the “missing active execution role” issue: the notebook is now in service and bound to a valid, policy‑backed IAM execution role.
      </Accordion>

      <Accordion title="Using Python">
        Here’s how to remediate a SageMaker Notebook Instance with a missing or inactive execution role using Python (boto3).

        ***

        ## 1. Prerequisites

        * `boto3` installed and configured (`aws configure`)
        * Permissions to manage IAM roles and SageMaker:
          * `iam:CreateRole`, `iam:AttachRolePolicy`
          * `sagemaker:UpdateNotebookInstance`, `sagemaker:StartNotebookInstance`, `sagemaker:DescribeNotebookInstance`

        ***

        ## 2. Create (or Recreate) an Execution Role

        Use an IAM role trusted by SageMaker with appropriate policies.

        ```python theme={null}
        import json
        import boto3

        iam = boto3.client("iam")
        sagemaker_service_principal = "sagemaker.amazonaws.com"
        role_name = "sagemaker-notebook-execution-role"

        assume_role_policy = {
            "Version": "2012-10-17",
            "Statement": [
                {
                    "Effect": "Allow",
                    "Principal": {"Service": sagemaker_service_principal},
                    "Action": "sts:AssumeRole"
                }
            ]
        }

        # 1. Create the role
        response = iam.create_role(
            RoleName=role_name,
            AssumeRolePolicyDocument=json.dumps(assume_role_policy),
            Description="Execution role for SageMaker notebooks"
        )
        role_arn = response["Role"]["Arn"]
        print("Created role:", role_arn)

        # 2. Attach policies (adjust as needed)
        # Basic managed policy (example: full SageMaker access – tighten for prod)
        iam.attach_role_policy(
            RoleName=role_name,
            PolicyArn="arn:aws:iam::aws:policy/AmazonSageMakerFullAccess"
        )

        # If notebooks need S3 access, logging, etc., attach additional policies
        # iam.attach_role_policy(...)

        print("Attached policies to role.")
        ```

        If you already have a role you want to reuse, skip creation and just set `role_arn` to that role’s ARN.

        ***

        ## 3. Update the Notebook Instance to Use the Role

        You can change the execution role of an existing notebook instance via `UpdateNotebookInstance`.

        ```python theme={null}
        import boto3
        import time

        sm = boto3.client("sagemaker")
        notebook_instance_name = "your-notebook-instance-name"

        # 1. Ensure notebook is stopped
        def wait_for_status(name, desired_status):
            while True:
                resp = sm.describe_notebook_instance(NotebookInstanceName=name)
                status = resp["NotebookInstanceStatus"]
                if status == desired_status:
                    break
                print(f"Current status: {status}, waiting for {desired_status}...")
                time.sleep(15)

        # Stop if running
        resp = sm.describe_notebook_instance(NotebookInstanceName=notebook_instance_name)
        if resp["NotebookInstanceStatus"] == "InService":
            print("Stopping notebook instance...")
            sm.stop_notebook_instance(NotebookInstanceName=notebook_instance_name)
            wait_for_status(notebook_instance_name, "Stopped")

        # 2. Update the execution role
        print("Updating notebook role...")
        sm.update_notebook_instance(
            NotebookInstanceName=notebook_instance_name,
            RoleArn=role_arn
        )

        # Wait for the update to complete (status returns to Stopped)
        wait_for_status(notebook_instance_name, "Stopped")
        print("Notebook instance updated to use role:", role_arn)
        ```

        ***

        ## 4. Start the Notebook Instance Again

        ```python theme={null}
        print("Starting notebook instance...")
        sm.start_notebook_instance(NotebookInstanceName=notebook_instance_name)
        wait_for_status(notebook_instance_name, "InService")
        print("Notebook instance is back InService with a valid execution role.")
        ```

        ***

        ## 5. Optional: Detect Notebooks with Missing/Invalid Roles

        To scan for notebooks whose role is missing (IAM role deleted) or blank:

        ```python theme={null}
        from botocore.exceptions import ClientError

        def notebook_has_valid_role(ni_name):
            ni = sm.describe_notebook_instance(NotebookInstanceName=ni_name)
            role_arn = ni.get("RoleArn")
            if not role_arn:
                return False

            # Check that IAM role exists
            role_name = role_arn.split("/")[-1]
            try:
                iam.get_role(RoleName=role_name)
                return True
            except ClientError as e:
                if e.response["Error"]["Code"] == "NoSuchEntity":
                    return False
                raise

        def list_notebooks_with_invalid_roles():
            invalid = []
            paginator = sm.get_paginator("list_notebook_instances")
            for page in paginator.paginate():
                for ni in page["NotebookInstances"]:
                    name = ni["NotebookInstanceName"]
                    if not notebook_has_valid_role(name):
                        invalid.append(name)
            return invalid

        print("Notebooks with missing/invalid roles:")
        print(list_notebooks_with_invalid_roles())
        ```

        You can then loop over that list and apply the update steps from sections 2–4 to remediate each notebook.
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
