Create AWS User Group & Policies
Go to IAM --> User Group --> Create a new User Group
Add permissions --> Attach Policies --> Add below standard policies:
Amazon EC2FullAccess
AmazonVPCFullAccess
AWSAccountUsageReportAccess
IAMReadOnlyAccess

Now to work with SAP CAL, we need more inline policies:
Add below inline policy as JSON format.

You can check the details from the standard AWS document for SAP CAL.
https://caldocs.hana.ondemand.com/caldocs/help/AWS_FAQs.pdf
Or simply copy below JSON for your inline policy:
Last updated