aws-secure-environment-accelerator icon indicating copy to clipboard operation
aws-secure-environment-accelerator copied to clipboard

[FEATURE] Add section to FAQ on setting up a role for use by Azure Sentinel using the legacy CloudTrail method

Open para0056 opened this issue 2 years ago • 0 comments

Required Basic Info To properly assess the enhancement request, we require information on the version of the Accelerator you based this request upon:

  • Accelerator Version: 1.5.3

Is your feature request related to a problem? Please describe. The Azure Sentinel S3 Connector is still in "preview", so we are continuing to use the Legacy CloudTrail Connector method. It is related to our use of Azure Sentinel using the legacy CloudTrail method.

Describe the solution you'd like We would like to be able to use the ASEA to create the required role for the Azure Sentinel CloudTrail data connector in all accounts in our Organization. The manual setup of this role is documented here: https://learn.microsoft.com/en-us/azure/sentinel/connect-aws?tabs=ct#prerequisites-2

Describe alternatives you've considered We've considered using CloudFormation StackSets to create this role. However, the Quarantine-New-Object SCP accounts prevents the successful execution of the stack instance on new accounts as they are vended.

para0056 avatar Sep 22 '22 19:09 para0056