Skip to main content
Cloud providers use organization-level hierarchies to group accounts, projects, or subscriptions and apply access and governance consistently. Prowler uses these hierarchies to discover cloud targets and help configure multi-account or multi-project scanning. This guide explains the shared lifecycle and the differences between AWS Organizations, Google Cloud organizations, and Azure Management Groups. Use the provider-specific guides for commands, permissions, and limitations.

Organization Lifecycle

Organization-level onboarding generally follows these steps:
  1. Identify the hierarchy: Locate the organization, management account, management group, folder, organizational unit, or equivalent parent node in the cloud provider.
  2. Grant access: Assign the provider permissions required to enumerate the hierarchy and read the resources that Prowler scans.
  3. Discover members: Use Prowler to retrieve accounts, projects, or subscriptions under the selected hierarchy.
  4. Select scan targets: Choose the cloud targets to connect or scan. Discovery does not necessarily make every discovered target a Prowler provider.
  5. Test access: Confirm that Prowler can authenticate to each selected target and read its resources.
  6. Scan and maintain: Run scans, review findings, and repeat discovery when the provider hierarchy changes.
Organization membership changes are not automatically synchronized in every Prowler workflow. Follow the provider-specific guide to learn when manual rediscovery is required.

Capability Matrix

Provider Guides

AWS Organizations

The AWS Organizations guide covers account details, delegated administration, IAM roles, CloudFormation StackSets, and CLI scanning. For Prowler Cloud onboarding, see AWS Organizations in Prowler Cloud.

Google Cloud Organization

The Google Cloud organization guide covers scanning projects under an organization ID, organization-level permissions, and Cloud Asset API requirements. For Prowler Cloud onboarding, see Google Cloud organizations in Prowler Cloud.

Azure Management Groups

The Azure Management Groups guide covers hierarchy setup, role assignment, subscription scope, and Azure-specific limitations. For Prowler Cloud onboarding, see Azure Management Groups in Prowler Cloud.

Scope Boundaries

The organization concepts in this guide refer only to cloud-provider resource hierarchies:
  • GitHub organizations group repositories and GitHub resources. They are a separate provider concept and are not part of AWS, Google Cloud, or Azure organization discovery.
  • MongoDB Atlas organizations group Atlas projects and teams. They use a separate provider API and authentication model.
  • Prowler Cloud organizations are internal tenants that isolate providers, scans, findings, users, and permissions. They are not the same as a cloud-provider organization and do not replace one.
Choose the guide that matches the hierarchy being configured, then use the relevant Prowler Cloud or CLI workflow for the scan targets.