Organization Lifecycle
Organization-level onboarding generally follows these steps:- Identify the hierarchy: Locate the organization, management account, management group, folder, organizational unit, or equivalent parent node in the cloud provider.
- Grant access: Assign the provider permissions required to enumerate the hierarchy and read the resources that Prowler scans.
- Discover members: Use Prowler to retrieve accounts, projects, or subscriptions under the selected hierarchy.
- Select scan targets: Choose the cloud targets to connect or scan. Discovery does not necessarily make every discovered target a Prowler provider.
- Test access: Confirm that Prowler can authenticate to each selected target and read its resources.
- Scan and maintain: Run scans, review findings, and repeat discovery when the provider hierarchy changes.
Organization membership changes are not automatically synchronized in every Prowler workflow. Follow the provider-specific guide to learn when manual rediscovery is required.
Capability Matrix
Provider Guides
AWS Organizations
The AWS Organizations guide covers account details, delegated administration, IAM roles, CloudFormation StackSets, and CLI scanning. For Prowler Cloud onboarding, see AWS Organizations in Prowler Cloud.Google Cloud Organization
The Google Cloud organization guide covers scanning projects under an organization ID, organization-level permissions, and Cloud Asset API requirements. For Prowler Cloud onboarding, see Google Cloud organizations in Prowler Cloud.Azure Management Groups
The Azure Management Groups guide covers hierarchy setup, role assignment, subscription scope, and Azure-specific limitations. For Prowler Cloud onboarding, see Azure Management Groups in Prowler Cloud.Scope Boundaries
The organization concepts in this guide refer only to cloud-provider resource hierarchies:- GitHub organizations group repositories and GitHub resources. They are a separate provider concept and are not part of AWS, Google Cloud, or Azure organization discovery.
- MongoDB Atlas organizations group Atlas projects and teams. They use a separate provider API and authentication model.
- Prowler Cloud organizations are internal tenants that isolate providers, scans, findings, users, and permissions. They are not the same as a cloud-provider organization and do not replace one.

