쿠키 기본 설정 선택

당사는 사이트와 서비스를 제공하는 데 필요한 필수 쿠키 및 유사한 도구를 사용합니다. 고객이 사이트를 어떻게 사용하는지 파악하고 개선할 수 있도록 성능 쿠키를 사용해 익명의 통계를 수집합니다. 필수 쿠키는 비활성화할 수 없지만 '사용자 지정' 또는 ‘거부’를 클릭하여 성능 쿠키를 거부할 수 있습니다.

사용자가 동의하는 경우 AWS와 승인된 제3자도 쿠키를 사용하여 유용한 사이트 기능을 제공하고, 사용자의 기본 설정을 기억하고, 관련 광고를 비롯한 관련 콘텐츠를 표시합니다. 필수가 아닌 모든 쿠키를 수락하거나 거부하려면 ‘수락’ 또는 ‘거부’를 클릭하세요. 더 자세한 내용을 선택하려면 ‘사용자 정의’를 클릭하세요.

Get started with Trusted Remediator in AMS

포커스 모드
Get started with Trusted Remediator in AMS - AMS Advanced User Guide
이 페이지는 귀하의 언어로 번역되지 않았습니다. 번역 요청

Trusted Remediator is available in AMS at no additional charge. Trusted Remediator supports single account and multi-account configurations.

Onboard to Trusted Remediator

To onboard your AMS accounts to Trusted Remediator, email your Cloud Architects or Cloud Service Delivery Managers (CSDMs). In the email, include the following information:

  • AWS accounts: The twelve-digit account identification number. All accounts that you want to onboard to Trusted Remediator must belong to the same AMS Advanced customer.

    • Delegated administrator account: The account that is used for Trusted Advisor check configuration for single or multiple accounts.

    • Member accounts: These are the accounts linked to the delegated administrator account. These accounts inherit the configurations from the delegated administrator account. You can have one member account or multiple member accounts.

      Note

      Member accounts inherit the configurations from the delegated administrator account. If you need different configurations for specific accounts, then onboard multiple delegated administrator accounts with your preferred configurations. Plan the account structure and the configurations with your Cloud Architects before you onboard.

  • AWS Region: The AWS Region where your resources are located. For a list of AWS Regions, see AWS services by Region.

  • Remediation schedule and time: Your preferred remediation schedule (daily or weekly). Trusted Remediator gathers Trusted Advisor checks and initiates remediation at the scheduled time. For example, you can set the remediation schedule for 1:00 AM Sunday every week, Australian Eastern Standard Time.

  • Notification email: Trusted Remediator uses the notification email to notify you when your scheduled remediations complete.

    Note

    Review your applications and resources after every scheduled remediation. For additional support, contact AMS.

After you submit your onboard request with the required details to your CA or CSDM, AMS onboards your accounts to Trusted Remediator. Trusted Remediator uses AWS AppConfig, a capability of AWS Systems Manager, to define the configuration for the Trusted Advisor checks. These configurations are a set of attributes that are stored in AWS AppConfig. To prevent unauthorized charges to your resources, all supported Trusted Advisor checks are set to Inactive when accounts are onboarded to Trusted Remediator. These configurations help you to automatically remediate specific Trusted Advisor checks, or to assess and manually remediate the remaining checks. The configurations are highly customizable, allowing you to apply configurations for each Trusted Advisor check. For more information, see Configure Trusted Advisor check remediation in Trusted Remediator.

AMS configures your AWS accounts in Trusted Remediator

When onboarding is complete, your CA or CDSM notifies you and the default configurations are created in your delegated administrator AWS account. The configuration is stored in AWS AppConfig under the Trusted Remediator application. You can use the RFC Management | Trusted Remediator | Remediation configuration | Update to request configuration updates. For more information, see Configure Trusted Advisor check remediation in Trusted Remediator.

To view the default Trusted Remediator configurations, complete the following steps:

  1. Open the AWS Systems Manager console at https://console.aws.amazon.com/systems-manager/.

    Note

    Make sure that you're in the delegated administrator account.

  2. Choose Application Management, AppConfig.

  3. Select Trusted Remediator from the list of applications.

The following is an example of the AWS AppConfig console showing Trusted Remediator configurations:

An example of Trusted Remediator configurations in the AWS AppConfig console.

Choose the Trusted Advisor checks to remediate

By default, remediation execution mode is Inactive for all Trusted Advisor checks in your configuration. This prevents unauthorized remediation and protects resources. AMS provides curated SSM automation documents for Trusted Advisor check remediation.

To select the checks that you want to remediate with Trusted Remediator, complete the following steps:

  1. Review the list of supported Trusted Advisor checks and the name of the associated SSM automation documents to decide which checks you want to remediate with Trusted Remediator.

  2. Submit a Management | Trusted Remediator | Remediation configuration | Update request to update configuration for your selected Trusted Advisor checks. For instructions on how to select checks, see Configure Trusted Advisor check remediation in Trusted Remediator.

Track your remediations in Trusted Remediator

After you update your account-level configuration, Trusted Remediator creates OpsItems for each remediation. Trusted Remediator runs the SSM document for automated remediation of OpsItems according to your remediation schedule. For instructions on how to view all remediation OpsItems from the Systems Manager OpsCenter console, see Track remediations in Trusted Remediator.

Run manual remediations in Trusted Remediator

You can manually remediate Trusted Advisor checks using an automated RFC. When you choose manual remediation, Trusted Remediator creates a manual execution OpsItem. For more information, see Run manual remediations in Trusted Remediator.

프라이버시사이트 이용 약관쿠키 기본 설정
© 2025, Amazon Web Services, Inc. 또는 계열사. All rights reserved.