Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Multi-Account Landing Zone viewing the compliance status of your AWS Config Rules

Focus mode
Multi-Account Landing Zone viewing the compliance status of your AWS Config Rules - AMS Advanced User Guide

AMS multi-account landing zone utilizes the AWS Config aggregator service to create a centralized view of compliance across all your accounts. This means you can see the compliance status of all AWS Config Rules across your AMS multi-account landing zone environment under the AWS Config aggregator in your security account.

The following is a sample of the AWS Config aggregator showcasing central compliance status of AWS Config Rules across accounts.

AWS Config dashboard showing compliant rules across regions and accounts.

For more information, see the AWS documentation for Config Aggregator.

  • How does AMS use AWS Config rules?

    AMS creates AWS Config Rules to give visibility into the configuration of your AWS resources against conditions specified in the rules. If a rule is non-compliant, you can request a change and the AMS Ops team will work with you to take corrective action.

  • In that case, you see the following changes appear in your AMS accounts:

    • AWS Config Rules under AWS Config > Rules

    • Custom Config rules with their Lambda functions exist in your account

    • Config Aggregator in Security account and Config Authorization in all accounts (Multi-Account Landing Zone only)

The following is a sample of AWS Config Rules and their compliance evaluation results is shown below:

AWS Config Rules dashboard showing compliant status for multiple security-related rules.

To learn more about AWS Config, see:

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.