AWSHow-To & HardeningRetrospectives

How to Enable GuardDuty Across an AWS Organization in One Afternoon

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.

Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.

Step 1: Pick a delegated administrator

In the GuardDuty console of your management account, designate a security tooling account as the delegated administrator. Do this in each region you use. Running security services from a dedicated account follows the AWS Security Reference Architecture.

Step 2: Auto-enable for all accounts

From the delegated administrator account, enable GuardDuty for all existing member accounts and turn on auto-enable so new accounts are covered automatically.

Step 3: Choose protection plans

Beyond the foundational data sources, decide which plans fit your environment:

  • S3 Protection for data access anomalies — recommended for nearly everyone.
  • EKS Protection and Runtime Monitoring if you run containers.
  • Malware Protection for EC2 and S3.
  • RDS Protection for Aurora login anomalies.
  • Lambda Protection for serverless network activity.

Use the usage statistics after 30 days to check costs.

Step 4: Cover every region

Attackers often operate in regions you do not use. Enable GuardDuty in all enabled regions, or disable unused regions entirely with an SCP.

Step 5: Route findings

Send findings to Security Hub and to an alerting channel through EventBridge. High-severity findings should reach a person, not just a dashboard.

Step 6: Prevent tampering

Use an SCP to deny guardduty:DeleteDetector, guardduty:DisassociateFromMasterAccount and similar actions in member accounts.

enable guardduty organizationAmazon GuardDuty2017

More on this story