

# Managing Amazon Config Rules Across All Accounts in Your Organization
<a name="config-rule-multi-account-deployment"></a>

**Important**  
Organizational rules can only be created using the API or CLI. This operation is not supported in the Amazon Config console.

Amazon Config allows you to manage Amazon Config rules across all Amazon Web Services accounts within an organization. You can:
+ Centrally create, update, and delete Amazon Config rules across all accounts in your organization. 
+ Deploy a common set of Amazon Config rules across all accounts and specify accounts where Amazon Config rules should not be created.
+ Use the APIs from the management account in Amazon Organizations to enforce governance by ensuring that the underlying Amazon Config rules are not modifiable by your organization’s member accounts.

## Considerations
<a name="config-rule-multi-account-deployment-considerations"></a>

**For deployments across different regions**

The API call to deploy rules and conformance packs across accounts is Amazon Region specific. At the organization level, you need to change the context of your API call to a different region if you want to deploy rules in other regions. For example, to deploy a rule in US East (N. Virginia), change the region to US East (N. Virginia) and then call `PutOrganizationConfigRule`.

**For accounts within an organization**

If a new account joins an organization, the rule or conformance pack is deployed to that account. When an account leaves an organization, the rule or conformance pack is removed.

If you deploy an organizational rule or conformance pack in an organization administrator account, and then establish a delegated administrator and deploy an organizational rule or conformance pack in the delegated administrator account, you won't be able to see the organizational rule or conformance pack in the organization administrator account from the delegated administrator account or see the organizational rule or conformance pack in the delegated administrator account from organization administrator account. The [DescribeOrganizationConfigRules](https://docs.amazonaws.cn/config/latest/APIReference/API_DescribeOrganizationConfigRules.html) and [DescribeOrganizationConformancePacks](https://docs.amazonaws.cn/config/latest/APIReference/API_DescribeOrganizationConformancePacks.html) APIs can only see and interact with the organization-related resource that were deployed from within the account calling those APIs. 

**Retry mechanism for new accounts added to an organization**

Deployment of existing organizational rules and conformance packs will only be retried for 7 hours after an account is added to your organization if a recorder is not available. You are expected to create a recorder if one doesn't exist within 7 hours of adding an account to your organization.

**Organization management accounts, delegated administrators, and service-linked roles**

If you are using an organization management account and intend to use a delegated administrator for organizational deployment, be aware that Amazon Config won't automatically create the service-linked role (SLR). You must manually create the service-linked role (SLR) separately using IAM.

If you do not have an SLR for your management account, you will not be able to deploy resources to that account from a delegated administrator account. You will still be able to deploy Amazon Config rules to member accounts from management and delegated administrator accounts. For more information, see [Using service-linked roles](https://docs.amazonaws.cn/IAM/latest/UserGuide/using-service-linked-roles.html) in the *Amazon Identity and Access Management (IAM) User Guide*.

## Deployment
<a name="config-rule-multi-account-deployment-deploy"></a>

For information on how to integrate Amazon Config with Amazon Organizations, see [Amazon Config and Amazon Organizations](https://docs.amazonaws.cn/organizations/latest/userguide/services-that-can-integrate-config.html) in the *Amazon Organizations User Guide*. Ensure Amazon Config recording is on before you use the following APIs to manage Amazon Config rules across all Amazon Web Services accounts within an organization:
+ [PutOrganizationConfigRule](https://docs.amazonaws.cn/config/latest/APIReference/API_PutOrganizationConfigRule.html), adds or updates organization config rule for your entire organization evaluating whether your Amazon resources comply with your desired configurations.
+ [DescribeOrganizationConfigRules](https://docs.amazonaws.cn/config/latest/APIReference/API_DescribeOrganizationConfigRules.html), returns a list of organization config rules.
+ [GetOrganizationConfigRuleDetailedStatus](https://docs.amazonaws.cn/config/latest/APIReference/API_GetOrganizationConfigRuleDetailedStatus.html), returns detailed status for each member account within an organization for a given organization config rule.
+ [GetOrganizationCustomRulePolicy](https://docs.amazonaws.cn/config/latest/APIReference/API_GetOrganizationCustomRulePolicy.html), returns the policy definition containing the logic for your organization config custom policy rule.
+ [DescribeOrganizationConfigRuleStatuses](https://docs.amazonaws.cn/config/latest/APIReference/API_DescribeOrganizationConfigRuleStatuses.html), provides organization config rule deployment status for an organization.
+ [DeleteOrganizationConfigRule](https://docs.amazonaws.cn/config/latest/APIReference/API_DeleteOrganizationConfigRule.html), deletes the specified organization config rule and all of its evaluation results from all member accounts in that organization.

## Region Support
<a name="region-support-org-config-rules"></a>

Deploying Amazon Config Rules across member accounts in an Amazon Organization is supported in the following Regions.


| Region Name | Region | Endpoint | Protocol | 
| --- | --- | --- | --- | 
| China (Beijing) | cn-north-1 |  config.cn-north-1.amazonaws.com.cn  | HTTPS | 
| China (Ningxia) | cn-northwest-1 |  config.cn-northwest-1.amazonaws.com.cn  | HTTPS | 