From 30eb4479197444b354d12968ad85ba2be5535334 Mon Sep 17 00:00:00 2001 From: Michael Dickinson <45626543+michael-dickinson-sainsburys@users.noreply.github.com> Date: Fri, 20 Nov 2020 08:41:49 +0000 Subject: [PATCH] docs: Update Organizations command to only incude active accounts --- README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index ff7c40d7..dcce9f50 100644 --- a/README.md +++ b/README.md @@ -296,9 +296,9 @@ or with a given External ID: If you want to run Prowler or just a check or a group across all accounts of AWS Organizations you can do this: -First get a list of accounts: +First get a list of accounts that are not suspended: ``` -ACCOUNTS_IN_ORGS=$(aws organizations list-accounts --query Accounts[*].Id --output text) +ACCOUNTS_IN_ORGS=$(aws organizations list-accounts --query Accounts[?Status==`ACTIVE`].Id --output text) ``` Then run Prowler to assume a role (same in all members) per each account, in this example it is just running one particular check: ``` @@ -647,4 +647,4 @@ Prowler is licensed as Apache License 2.0 as specified in each file. You may obt **I'm not related anyhow with CIS organization, I just write and maintain Prowler to help companies over the world to make their cloud infrastructure more secure.** -If you want to contact me visit or follow me on Twitter my DMs are open. \ No newline at end of file +If you want to contact me visit or follow me on Twitter my DMs are open.