Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Deleting Authorization for Aggregator Accounts to Collect AWS Config Configuration and Compliance Data

Focus mode
Deleting Authorization for Aggregator Accounts to Collect AWS Config Configuration and Compliance Data - AWS Config

Authorization refers to the permissions you grant to an aggregator account and region to collect your AWS Config configuration and compliance data. Authorization is not required if you are aggregating source accounts that are part of AWS Organizations. You can use the AWS Config console or the AWS CLI to delete authorizations.

Considerations

There are two types of aggregators: Individual account aggregator and Organization aggregator

For an individual account aggregator, authorization is required for all source accounts and Regions that you want to include, including both external accounts and Regions and Organization member accounts and Regions.

For an organization aggregator, authorization is not required for Organization member account regions since authorization is integrated with the AWS Organizations service.

Aggregators do not automatically enable AWS Config on your behalf

AWS Config needs to be enabled in the source account and Region for either type of aggregator, in order for AWS Config data to be generated in the source account and Region.

Deleting Authorization

Deleting Authorization (Console)
  1. Sign in to the AWS Management Console and open the AWS Config console at https://console.aws.amazon.com/config/.

  2. Choose the aggregator account that you want to delete authorization, and then choose Delete.

    A warning message is displayed. When you delete this authorization, AWS Config data will no longer be shared with the aggregator account.

  3. Choose Delete again to confirm your selection.

    The aggregator account is now deleted.

Deleting Authorization (AWS CLI)

Enter the following command:

aws configservice delete-aggregation-authorization --authorized-account-id AccountID --authorized-aws-region Region

If successful, the command executes with no additional output.

  1. Sign in to the AWS Management Console and open the AWS Config console at https://console.aws.amazon.com/config/.

  2. Choose the aggregator account that you want to delete authorization, and then choose Delete.

    A warning message is displayed. When you delete this authorization, AWS Config data will no longer be shared with the aggregator account.

  3. Choose Delete again to confirm your selection.

    The aggregator account is now deleted.

On this page

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.