GuardDuty Delegate Admin doesn't have GD enabled

0

We enabled GuardDuty at the Org-level and delegated the primary/management Account. However, in the GD console at the delegated account, the primary/management Account isn't listed. It seems as though the delegate admin doesn't have GuardDuty enabled.

How do you enable GD detections on the delegate admin when it is also the primary/management Account?

Might be similar to https://repost.aws/questions/QULax-FQ6UQHW0gcW8qwEIPQ/iam-access-analyzer-delegated-admin-and-org-configuration-doesnt-pick-up-root-account

1개 답변
0

Hi There

An account that is designated as a delegated administrator becomes a GuardDuty administrator account, has GuardDuty automatically enabled in the designated Region, and is granted permission to enable and manage GuardDuty for all accounts in the organization within that Region. The other accounts in the organization can be viewed and added as GuardDuty member accounts associated with the delegated administrator account.

Not recommended to set your organization's management account as the delegated administrator. Your organization's management account can be the delegated administrator, but this is not recommended based on AWS Security best practices following the principle of least privilege.

Ref: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_organizations.html

profile pictureAWS
전문가
Matt-B
답변함 2년 전
profile picture
전문가
검토됨 22일 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠