How to Enable GuardDuty Across an AWS Organization in One Afternoon
Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.
Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.
Step 1: Pick a delegated administrator
In the GuardDuty console of your management account, designate a security tooling account as the delegated administrator. Do this in each region you use. Running security services from a dedicated account follows the AWS Security Reference Architecture.
Step 2: Auto-enable for all accounts
From the delegated administrator account, enable GuardDuty for all existing member accounts and turn on auto-enable so new accounts are covered automatically.
Step 3: Choose protection plans
Beyond the foundational data sources, decide which plans fit your environment:
- S3 Protection for data access anomalies — recommended for nearly everyone.
- EKS Protection and Runtime Monitoring if you run containers.
- Malware Protection for EC2 and S3.
- RDS Protection for Aurora login anomalies.
- Lambda Protection for serverless network activity.
Use the usage statistics after 30 days to check costs.
Step 4: Cover every region
Attackers often operate in regions you do not use. Enable GuardDuty in all enabled regions, or disable unused regions entirely with an SCP.
Step 5: Route findings
Send findings to Security Hub and to an alerting channel through EventBridge. High-severity findings should reach a person, not just a dashboard.
Step 6: Prevent tampering
Use an SCP to deny guardduty:DeleteDetector, guardduty:DisassociateFromMasterAccount and similar actions in member accounts.
- Amazon GuardDuty Launches at re:Invent 2017: Managed Threat Detection for AWS Platform Changes
- GuardDuty Finding Triage Runbook for Small Security Teams How-To & Hardening
- CIO Brief: Managed Threat Detection — Build vs. Buy for AWS CIO Briefings