Skip to main content
Prowler enables security scanning across multiple AWS accounts by utilizing the Assume Role feature and integration with AWS Organizations feature. This approach allows execution from a single account with permissions to assume roles in the target accounts.

Scanning Multiple Accounts Sequentially

To scan specific accounts one at a time:
  • Define a variable containing the AWS account IDs to be scanned:
  • Run Prowler with an IAM role that exists in all target accounts: (replace the <role_name> with to yours, that is to be consistent throughout all accounts):

Scanning Multiple Accounts in Parallel

  • To scan multiple accounts simultaneously:
Define the AWS accounts to be scanned with a variable:
  • Run Prowler with an IAM role that exists in all target accounts: (replace the <role_name> with to yours, that is to be consistent throughout all accounts). The following example executes scanning across three accounts in parallel:

Scanning Multiple AWS Organization Accounts in Parallel

Prowler enables parallel security scans across multiple AWS accounts within an AWS Organization.

Retrieve Active AWS Accounts

To efficiently scan multiple accounts within an AWS Organization, follow these steps:
  • Step 1: Retrieve a List of Active Accounts
First, declare a variable containing all active accounts in your AWS Organization. Run the following command in your AWS Organizations Management account, ensuring that you have the necessary permissions:
  • Step 2: Run Prowler with Assumed Roles
Use Prowler to assume roles across accounts in parallel. Modify <role_name> to match the role that exists in all accounts and <management_organizations_account_id> to your AWS Organizations Management account ID.