EC2 Scan & AWS Estate Discovery
The Both option in DMC runs an EC2 Scan and an AWS Estate Discovery together in a single pass, giving Dr Migrate in-guest server data, CloudWatch metrics, and a complete AWS resource and cost inventory without a second scan run.
Before you start¶
Complete all prerequisites from both the EC2 Scan and AWS Estate Discovery pages before proceeding:
- A collector host inside your AWS environment (Windows, outbound HTTPS 443 to AWS service endpoints)
- A collector identity (IAM role) with permission to assume the scan role in each target account
- A scan role in every target account, combining the EC2 Scan and AWS Estate Discovery permissions policies
- One in-server access method configured (SSM recommended, or SSH/WinRM) for EC2 Scan
- AWS Config and Cost Explorer enabled for Estate Discovery
- Admin-level credentials for target servers (EC2 Scan only)
Running the scan¶
Launch DMC on the collector host and follow the wizard to configure and run the scan.
If only your own account appears here, organizations:ListAccounts may be blocked at the AWS Organizations level rather than by IAM. See AWS Requirements for how to enable multi-account discovery.

