AWS Config aggregator limited to selected Regions

Check that aggregation covers the Regions required for central assessment.

Description

An AWS Config aggregator limited to selected Regions can omit other Regions’ configuration and compliance data from central queries. AllAwsRegions includes current and future supported Regions in the aggregation scope.

Potential impact

A scope narrower than the assessment requirements can leave resources or compliance violations out of central reports.

Remediation

Set AllAwsRegions: true on the account or organization aggregation source when all-Region aggregation is required. AWS Config recording and the necessary aggregation authorization must also be configured at the sources.

Examples

The examples change one account from selected-Region to all-Region aggregation. An aggregator setting does not itself enable recording in source accounts.

Before

yaml
Resources:
  ConfigAggregator:
    Type: AWS::Config::ConfigurationAggregator
    Properties:
      AccountAggregationSources:
        - AccountIds:
            - "123456789012"
          AwsRegions:
            - us-west-2
          AllAwsRegions: false

After

yaml
Resources:
  ConfigAggregator:
    Type: AWS::Config::ConfigurationAggregator
    Properties:
      AccountAggregationSources:
        - AccountIds:
            - "123456789012"
          AllAwsRegions: true

References