Quickly add your accounts to Cloud Accounts by connecting your AWS Organization.
Cloud Accounts supports adding accounts managed by your AWS Organization by deploying
features to the root account or organizational unit (OU) level. Adding your AWS
Organization to Cloud Accounts provides a quick way to allow Trend Vision One access to your managed cloud accounts to provide
security and visibility into your cloud assets. Some Cloud Account features have
limited support for AWS regions. For more information, see AWS supported regions and
limitations.
Before you begin, ensure you have access to a sign-in or user role with administrator
privileges, including permissions to create and manage AWS CloudFormation stack sets
for the AWS Organization you wish to connect. For more information, see AWS CloudFormation StackSets and AWS
Organizations.
![]() |
Important
|
Procedure
- Sign in to the Trend Vision One console.
- In the Trend Vision One console, go to .
- Click Add Account.The Add Cloud Account window appears.
- Select AWS Organization.
- Specify the general information for the organization.
- Specify the Organization name
to display in the Cloud Accounts app.Once the AWS Organization is added, all member accounts without a previously specified alias in AWS receive an automatically generated name in the Cloud Accounts app.
- Specify a Description to display in the Cloud Accounts app.
- Specify the Organization name
to display in the Cloud Accounts app.
- Select the AWS region for CloudFormation template
deployment.
Note
The default region is based on your Trend Vision One region.Some features and permissions have limited support for some AWS regions. For more information, see AWS supported regions and limitations. - If you are not already signed into your AWS account using a role that has administrator privileges, click Go to AWS to do so in the same browser session.
- Click Next.
- Choose which Features and
Permissions to enable on the account.
-
Core Features: Connect your AWS account to Trend Vision One to discover your cloud assets and rapidly identify risks such as compliance and security best practice violations on your cloud infrastructure.
-
Container Protection for Amazon ECS: Deploy Trend Vision One Container Security in your AWS account to protect your containers and container images in Elastic Container Service (ECS) environments. Trend Vision One Container Security uncovers threats and vulnerabilities, protects your runtime environment, and enforces deployment policies.
Note
As of November 2023, AWS private and freemium accounts only allow a maximum of 10 Lambda executions. Container Protection deployment requires at least 20 concurrent Lambda executions. Please verify your AWS account status before enabling this feature.
Note
Only the above listed features and permissions support deployment to organization managed accounts. Additional features and permissions can only be deployed to single accounts. -
- Click Next.
- If you have more than one Server & Workload
Protection Manager instance, select the instance to associate with the connected
account.
Note
If you only have one Server & Workload Protection Manager instance, the account is automatically associated with that instance. - Launch the CloudFormation template in the AWS
console.
- If you want to review the stack template before launching, click Download and Review Template.
- Click Launch Stack.The AWS management console opens in a new tab and displays the Quick Create Stack screen.
- In the AWS management console, complete the steps
in the Quick Create Stack screen.
- If you want to use a name other than the default, specify a new Stack name.
- In the Parameters section, input the AWS
Account ID or the Organizational Unit (OU) ID in
the OrganizationID field.
Important
Do not change any other settings in the Parameters section. CloudFormation automatically provides the settings for the parameters. Changing parameters might cause stack creation to fail. - In the Capabilities
section, select the following acknowledgments:
-
I acknowledge that AWS CloudFormation might create IAM resources with custom names.
-
I acknowledge that AWS CloudFormation might require the following capability: CAPABILITY_AUTO_EXPAND.
-
- Click Create Stack.The Stack details screen for the new stack appears with the Events tab displayed. Creation might take a few minutes. Click Refresh to check the progress.
- In the Trend Vision One console, click
Done.The organization and its member accounts appear in Cloud Accounts once the CloudFormation template deployment is completed. Refresh the screen to update the table.