Permissions required for Amazon IAM user
With the Amazon (S3) cloud vendor, if you have configured an IAM user, it should have following minimum permissions to work with NetBackup:
s3:CreateBucket
s3:ListAllMyBuckets
s3:ListBucket
s3:GetBucketLocation
s3:GetObject
s3:PutObject
s3:DeleteObject
For more information refer to the AWS Identity and Access Management documentation.
For Amazon Glacier, you need additional permissions. See Protecting data in Amazon Glacier for long-term retention.