How to turn on Trusted Access on CloudTrail

0
  1. I am wondering where about on CloudTrail I can turn on Trusted Access as directerd by AWS Organisation->Services page. When I click Enable Trusted Access a window prompted me enable trusted access using the CloudTrail console.

  2. I am also not sure if I should use Trusted Access, Delegated Admnistrator or just add a policy to the organisation unit account to allow permission to CloudTrail.

profile picture
Lottie
질문됨 4달 전265회 조회
1개 답변
2
수락된 답변

Hi Hannah,

To enable Trusted Access for CloudTrail across your Organization from the CloudTrail Console, you can create an Organization trail, as mentioned in the docs here: [1].

If you enable trusted access by creating a trail from the AWS CloudTrail console, trusted access is configured automatically for you (recommended).

Remember to check the box Enable for all accounts in my organization, as you can see in the screenshot below:
Screenshot

Furthermore, in my opinion, you should choose to use "Delegated Administrator", since it will be a member account that can perform administrative tasks like creating trails and event data stores on behalf of the entire organization. In that case, you can minimize using your "Management" account to perform administrative tasks.
Alternatives like adding individual policies to accounts or organization units would require more ongoing maintenance and lack centralized visibility compared to using a delegated administrator.

References:
[1] https://docs.aws.amazon.com/organizations/latest/userguide/services-that-can-integrate-cloudtrail.html#integrate-enable-ta-cloudtrail
[2] https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-an-organizational-trail-in-the-console.html

Thanks,
Atul

profile picture
답변함 4달 전
profile pictureAWS
전문가
검토됨 4달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인