Amazon GuardDuty now supports centralized management using AWS Organizations declarative policies

Amazon GuardDuty Declarative Policies Support
Amazon GuardDuty now supports AWS Organizations declarative policies, enabling you to centrally enable GuardDuty threat detection across every account and Region in your AWS organization. Using an organization policy, you can apply a centrally managed GuardDuty enablement configuration that applies to existing accounts and is automatically maintained as new accounts join your organization.
Enabling GuardDuty across all relevant accounts and Regions helps ensure comprehensive threat detection coverage. Previously, keeping enablement aligned across a large multi-account, multi-Region environment meant configuring GuardDuty's enablement settings separately in each Region, which could drift over time. Now you can define a central GuardDuty policy from your delegated administrator account that sets an enablement baseline across your organization (at the organization root, OUs, or individual accounts). The policy supports a default configuration that applies in every Region where GuardDuty is available, as well as per-Region overrides for Regions that require different enablement. Enablement set by a policy cannot be overridden via the GuardDuty console or API.
What to do
- Ensure the delegated administrator has permission to manage GuardDuty policies.
- Sign in to the GuardDuty console and choose Organization policies.
- Create a policy programmatically using AWS Organizations APIs.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



