Enabling GuardDuty via Organisations

0

I would like to enable GuardDuty via Organisations, and would like to know whether the existing member accounts on the main administrative account (by invitation) switch to 'enabled via Organisations' automatically. Also, can I designate a GuardDuty administrator account from outside the organisation (being from a separate organisation).

2回答
2
承認された回答

If you have already set up a GuardDuty administrator with associated member accounts by invitation, and the member accounts are part of the same organization, their Type changes from by Invitation to via Organizations when you set a GuardDuty delegated administrator for your organization.

If the new delegated administrator previously added members by invitation that are not part of the same organization, their Type is by Invitation. In both cases, these previously added accounts are member accounts to the organization's GuardDuty delegated administrator.

You cannot designate an account outside of your organization as a GuardDuty administrator account.

profile pictureAWS
回答済み 2年前
AWS
エキスパート
Luca_I
レビュー済み 2年前
0

You cannot delegate Admin to an account outside of your organization as it uses Org based roles for access across the accounts.

You can find more information about enabling org wide integration in the AWS docs: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_organizations.html

profile pictureAWS
エキスパート
Rob_H
回答済み 2年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ