Responding to an invitation to be a Security Hub member account
Note
We recommend using AWS Organizations instead of Security Hub invitations to manage your member accounts. For information, see Managing Security Hub administrator and member accounts with Organizations.
You can accept or decline an invitation to be an AWS Security Hub member account.
If you accept an invitation, your account becomes a Security Hub member account. The account that sent the invitation becomes your Security Hub administrator account. The administrator account user can view findings for your member account in Security Hub.
If you decline the invitation, then your account is marked as Resigned on the administrator account's list of member accounts.
You can only accept one invitation to be a member account.
Before you can accept or decline an invitation, you must enable Security Hub.
Remember that all Security Hub accounts must have AWS Config enabled and configured to record all resources. For details on the requirement for AWS Config, see Enabling and configuring AWS Config.
Accepting an invitation
You can send an invitation to be a Security Hub member account from the administrator account. You can then accept the invitation after signing in to the member account.
Choose your preferred method, and follow the steps to accept an invitation to be a member account.
Note
The Security Hub console continues to use AcceptInvitation
. It will
eventually change to use AcceptAdministratorInvitation
. Any IAM
policies that specifically control access to this function must continue to use
AcceptInvitation
. You should also add
AcceptAdministratorInvitation
to your policies to ensure that
the correct permissions are in place after the console begins to use
AcceptAdministratorInvitation
.
Declining an invitation
You can decline an invitation to be a Security Hub member account. When you decline an invitation in the Security Hub console, your account is marked as Resigned on the administrator account's list of member accounts. The Resigned status appears only when you sign in to the Security Hub console using the administrator account. However, the invitation remains unchanged in the console for the member account until you sign in to the administrator account and delete the invitation.
To decline an invitation, you must sign in to the member account that received the invitation.
Choose your preferred method, and follow the steps to decline an invitation to be a member account.