1 Answer
- Newest
- Most votes
- Most comments
0
By default config recording is not turned on in the Master Account (root). A quick glance at the link you provided highlights some of them are prior to organization features which have been introduced for SecurityHub and IAM Access Analyzer. This feature will allow you to delegate these services to another account as noted in the here for SecurityHub and here for IAM Access Analyzer.
So one option is to enable Config on the Master Account although it is better to delegate these services to an account outside of the Master Account. If you delegate these services and also enable organizations for SecurityHub any new account vended via Control Tower will be added.
answered 2 years ago
Relevant content
- asked 6 months ago
- asked 7 months ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 3 months ago
- AWS OFFICIALUpdated 9 months ago