Amazon GuardDuty now supports centralized management using AWS Organizations declarative policies

Published
October 1, 2026
https://aws.amazon.com/about-aws/whats-new/2026/10/guardduty-org-enablement-policies/

Amazon GuardDuty Declarative Policies Support

Amazon GuardDuty now supports AWS Organizations declarative policies, enabling you to centrally enable GuardDuty threat detection across every account and Region in your AWS organization. Using an organization policy, you can apply a centrally managed GuardDuty enablement configuration that applies to existing accounts and is automatically maintained as new accounts join your organization.

Enabling GuardDuty across all relevant accounts and Regions helps ensure comprehensive threat detection coverage. Previously, keeping enablement aligned across a large multi-account, multi-Region environment meant configuring GuardDuty's enablement settings separately in each Region, which could drift over time. Now you can define a central GuardDuty policy from your delegated administrator account that sets an enablement baseline across your organization (at the organization root, OUs, or individual accounts). The policy supports a default configuration that applies in every Region where GuardDuty is available, as well as per-Region overrides for Regions that require different enablement. Enablement set by a policy cannot be overridden via the GuardDuty console or API.

What to do

  • Ensure the delegated administrator has permission to manage GuardDuty policies.
  • Sign in to the GuardDuty console and choose Organization policies.
  • Create a policy programmatically using AWS Organizations APIs.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.