Description
An AWS Config aggregator limited to selected Regions can omit other Regions’ configuration and compliance data from central queries. AllAwsRegions includes current and future supported Regions in the aggregation scope.
Potential impact
A scope narrower than the assessment requirements can leave resources or compliance violations out of central reports.
Remediation
Set AllAwsRegions: true on the account or organization aggregation source when all-Region aggregation is required. AWS Config recording and the necessary aggregation authorization must also be configured at the sources.
Examples
The examples change one account from selected-Region to all-Region aggregation. An aggregator setting does not itself enable recording in source accounts.
Before
Resources:
ConfigAggregator:
Type: AWS::Config::ConfigurationAggregator
Properties:
AccountAggregationSources:
- AccountIds:
- "123456789012"
AwsRegions:
- us-west-2
AllAwsRegions: false
After
Resources:
ConfigAggregator:
Type: AWS::Config::ConfigurationAggregator
Properties:
AccountAggregationSources:
- AccountIds:
- "123456789012"
AllAwsRegions: true