Amazon Web Services said on October 1, 2026 that Amazon GuardDuty now supports AWS Organizations declarative policies, allowing administrators to centrally enable the threat detection service across every account and Region in an AWS organization.
What changed
According to AWS, customers can now apply a centrally managed GuardDuty enablement configuration through an organization policy. The company said the configuration applies to existing accounts and is automatically maintained as new accounts join the organization.
AWS said that previously, keeping enablement aligned across a large multi-account, multi-Region environment meant configuring GuardDuty's enablement settings separately in each Region, which could drift over time.
How the policy works
The policy is defined from the delegated administrator account and sets an enablement baseline at the organization root, organizational units, or individual accounts, AWS said.
According to the company, the policy supports a default configuration that applies in every Region where GuardDuty is available, plus per-Region overrides for Regions that require different enablement. AWS said enablement set by a policy cannot be overridden via the GuardDuty console or API.
Availability
AWS said GuardDuty declarative policy support is available in all AWS commercial Regions and the AWS GovCloud (US) Regions.
The company pointed customers to the Amazon GuardDuty User Guide section on managing accounts using organization policies, and to the Amazon GuardDuty policies documentation in the AWS Organizations User Guide.
What to do
- Make sure the delegated administrator account has permission to manage GuardDuty policies before you begin, as AWS advises.
- Sign in to the GuardDuty console and choose Organization policies, or create a policy programmatically using AWS Organizations APIs.
- Set a default configuration for all Regions where GuardDuty is available, and add per-Region overrides for any Regions that need different enablement.
- Consult the Amazon GuardDuty User Guide page on managing accounts using organization policies and the Amazon GuardDuty policies page in the AWS Organizations User Guide for details.
Key facts and where they come from
- GuardDuty now supports AWS Organizations declarative policies for centralized enablement.
Amazon GuardDuty now supports AWS Organizations declarative policies, enabling you to centrally enable GuardDuty threat detection across every account and Region in your AWS organization.
- The configuration is automatically applied to accounts that join later.
The configuration applies to existing accounts and is automatically maintained as new accounts join your organization.
- Policy-set enablement cannot be changed from the GuardDuty console or API.
Enablement set by a policy cannot be overridden via the GuardDuty console or API.
- The feature is available in all commercial Regions and GovCloud (US).
GuardDuty declarative policy support is available in all AWS commercial Regions and the AWS GovCloud (US) Regions.
- Policies can target the organization root, OUs or individual accounts, with per-Region overrides.
sets an enablement baseline across your organization (at the organization root, OUs, or individual accounts)
