Deleting Authorization for Aggregator Accounts to Collect Amazon Config Configuration and Compliance Data
Authorization refers to the permissions you grant to an aggregator account and region to collect your Amazon Config configuration and compliance data. Authorization is not required if you are aggregating source accounts that are part of Amazon Organizations. You can use the Amazon Config console or the Amazon CLI to delete authorizations.
Considerations
There are two types of aggregators: Individual account aggregator and Organization aggregator
For an individual account aggregator, authorization is required for all source accounts and Regions that you want to include, including both external accounts and Regions and Organization member accounts and Regions.
For an organization aggregator, authorization is not required for Organization member account regions since authorization is integrated with the Amazon Organizations service.
Aggregators do not automatically enable Amazon Config on your behalf
Amazon Config needs to be enabled in the source account and Region for either type of aggregator, in order for Amazon Config data to be generated in the source account and Region.