AWS Organizations emits CloudTrail events for account membership changes
Share
Services
AWS Organizations now automatically emits CloudTrail events to your management account whenever accounts join or leave your organization. These new events—AccountJoinedOrganization and AccountDepartedOrganization—provide security teams and cloud administrators with enhanced visibility into organizational membership changes, helping detect unauthorized activities and potential security incidents that previously could go unnoticed. The AccountJoinedOrganization event captures how an account joined an organization (Created or Invited) and the join timestamp, while the AccountDepartedOrganization event records how an account departed —Left for accounts that departed voluntarily, Removed for accounts removed by the management account, or Cleaned for accounts that were permanently closed along with the departure timestamp. You can leverage these events to create CloudWatch alarms or Amazon EventBridge rules for real-time notifications, enabling rapid response to suspicious organizational changes. This capability supports critical use cases including fraud detection, compliance auditing, security monitoring, and incident investigation across your AWS environment. These CloudTrail events are available now in all commercial AWS Regions, the AWS GovCloud (US) Regions, and the China Regions. To learn more, visit [AWS Organizations documentation](https://docs.aws.amazon.com/organizations/latest/APIReference/Welcome.html).
What else is happening at Amazon Web Services?
Read update
Services
Share
Amazon Connect Customer expands generative AI-powered post-contact summaries to eight new languages
about 22 hours ago
Services
Share
DynamoDB Streams now supports AWS PrivateLink for FIPS endpoints in AWS GovCloud (US) Regions
about 23 hours ago
Services
Share
Amazon WorkSpaces Applications adds support for Windows Desktop OS
about 23 hours ago
Services
Share