Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

7.1.4. Centralized Security Service Management

First Principle: Security services must be enabled consistently across all accounts and Regions, managed from a central point, and monitored for gaps. Delegated administrator accounts enable this without using the sensitive management account.

Delegated Administrator Pattern:
  • Designate a security account as the delegated administrator for each security service
  • The delegated admin can manage the service across all organization accounts
  • No need to use the management account for day-to-day security operations
Services Supporting Delegated Admin:
ServiceWhat the Admin Manages
GuardDutyThreat detection across all accounts/Regions
Security HubFinding aggregation and security standards
InspectorVulnerability scanning across all accounts
MacieSensitive data discovery across all accounts
ConfigCompliance rules and aggregation
Firewall ManagerWAF, SG, and Network Firewall policies
DetectiveInvestigation across all accounts
Implementation:
  1. Create a dedicated Security account
  2. Register it as delegated administrator for each service
  3. Enable auto-enable for new accounts (so new accounts automatically get security services)
  4. Configure cross-Region aggregation where supported

⚠️ Exam Trap: Each service has its own delegated admin registration. You can (and should) use the same Security account for all, but each service must be registered individually.

Scenario: The security team manages GuardDuty, Security Hub, and Inspector from a dedicated Security account. When a new team creates an AWS account via Account Factory, all three services are automatically enabled and the Security account gains visibility immediately.

Reflection Question: Why is the delegated administrator model preferred over managing security services from the management account?

Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications