> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/aws/connect-aws-organization-to-aikido.md).

# AWS Organization を接続する

{% hint style="info" %}
この機能は、 **Pro** および **Advanced** プラン。 **お問い合わせください** 詳細はチャットでお問い合わせください。
{% endhint %}

多くのメンバーアカウントを持つ AWS Organization がある場合は、次のものだけを接続できます [管理アカウント](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_getting-started_concepts.html#management-account) そして、Aikido が残りの AWS アカウントを自動的に検出して接続するようにします。

## AWS Organization を接続する理由

組織レベルでオンボーディングすることで、次の利点があります:

* **セットアップの高速化**: 接続するのは管理アカウントだけで済みます。
* **アカウントの自動検出**: 新しいメンバーアカウントは、自動的に Aikido に追加されます。将来作成するアカウントも含まれます。

## 前提条件

* Pro、Advanced、または Enterprise プランをご利用です。
* AWS Organization の AWS 管理アカウントにアクセスできます。
* 次のものがあります [AWS CloudFormation StackSets の Trusted Access を有効にしています](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-orgs-activate-trusted-access.html).

## はじめに

AWS Organization を接続するには、'Full AWS Organizatio&#x6E;**'** オプションを [AWS 接続ウィザードで選択してください](https://app.aikido.dev/clouds/add/aws)。次の情報を提供する必要があります:

* **Organization ID**: 'o-wma21z4agr' のような形式です。
* **ルート ID** または 1 つ以上の **組織単位（OU）ID**をカンマ区切りで指定します: このオプションでは、組織全体（ルート ID を指定）またはその一部のみ（たとえば、本番とステージングの OU のみを接続したい場合など）を接続できます。
* **除外するアカウント ID**: 必要に応じて、特定の AWS アカウントを Aikido に追加しないように除外できます。

この情報は、次の場所から取得できます: [AWS Organization のページ](https://us-east-1.console.aws.amazon.com/organizations/v2/home/accounts).

<figure><img src="/files/161cca3dbb648dc7872b2e5fdbc67acaeef85ef8" alt=""><figcaption></figcaption></figure>

セットアップが完了すると、数分以内にすべての AWS アカウントが Aikido に接続されているのが表示されます。

### クラウド用途の判定

AWS アカウントの目的/環境は、親 OU の名前に基づいて自動的に判定されます。Aikido は "production"、"staging"、"uat" などの用語を探し、それに応じてクラウドの目的を設定します。一致するものが見つからない場合、目的は "mixed" になります。各クラウド接続の目的は、"Configure" ボタンを使って手動で更新できます。

### メンバーアカウント向けの ECR/EBS スキャン

Aikido は、AWS メンバーアカウントに対して ECR スキャンおよび/または EBS（EC2）スキャンを自動で設定できます。これらを有効にすると、CloudFormation StackSet に追加の IAM リソース（各機能ごとに IAM ロールとカスタムポリシー）がデプロイされます。AWS アカウントで CloudFormation ページを開く前に、必要に応じてこれらのオプションを設定してください。

まだ AWS Organization を接続していない場合は、初期セットアップ中にこれらを有効にできます。"Enable EBS Scanning" オプションが表示されない場合は、お問い合わせください。

#### オンボーディング後の Organization 詳細の編集

組織固有の値（例: 除外する AWS アカウント）を更新するには **～の後に** AWS Organization のオンボーディングを完了した後、次の手順が必要です:

1. CloudFormation スタックのパラメータを更新します。
   1. 〜を開き `aikido-security-readonly-org` CloudFormation スタック。
   2. 「Update stack」→「Make a direct update」。
   3. 既定の「Use existing template」オプションを選択します。
   4. 必要に応じてパラメータを更新します。
   5. 次のページで、IAM リソースの作成を承認します。
   6. 「Submit」を押します。変更のデプロイには数分かかります。
2. Aikido で「Clouds」に移動し、AWS 管理アカウントに対応するクラウドの「Configure」を選択して設定を更新します。

<figure><img src="/files/d4667652702fbcd988206fddde11715cd39a17f7" alt=""><figcaption></figcaption></figure>

3. Aikido で管理アカウントのスキャンを実行します。これにより、新しい AWS アカウントが検出されます。AWS アカウントを除外した場合（または OU を削除した場合）は、Aikido から該当するクラウドを削除してください。

## FAQ

1. **安全ですか？**

はい。AWS Organization の接続は、個別の AWS アカウントを接続する際と同じ設定に基づいており、外部 ID を必要とする最小権限の IAM ロールを使用します。実際には同じテンプレートで、AWS アカウントごとに CloudFormation StackSets を使ってデプロイしているだけです。

2. **AWS アカウントを組織に追加すると、Aikido に表示されますか？**

はい。Aikido は管理アカウントをスキャンするたびに AWS Organization をスキャンし、新しい AWS アカウントを自動的に接続します。このプロセスは、AWS CloudFormation StackSets によって支えられており、AWS アカウント内に必要な IAM ロールとポリシーが自動的に作成されます。

3. **組織に新しい AWS アカウントを追加したのに、Aikido に表示されませんでした。**

Aikido が AWS 管理アカウントをスキャン済みで（手動でスキャンすることもできます）、それでも新しいアカウントが表示されない場合は、プランのクラウドアカウント上限に達している可能性があります。上限の引き上げについてご連絡ください。

4. **AWS アカウントを停止したり、AWS Organization から削除したりするとどうなりますか？**

Aikido は、そのアカウントがもはやアクティブでない、または組織の一部ではないことを検出し、対応する接続を「到達不可」としてマークします。これは次の場所で確認できます: [Clouds ページ](https://app.aikido.dev/clouds).

5. **必要な AWS リソースを Terraform でセットアップできますか？**

はい。次を使用できます: [Terraform モジュール](https://github.com/AikidoSec/aws-native-terraform-module)。主なバリアントは AWS CloudFormation StackSet を作成します。StackSets が使用できない場合は、次を検討してください: [IAM サブモジュール](https://github.com/AikidoSec/aws-native-terraform-module/tree/main/modules/iam-roles) を使って各 AWS アカウントにロールを作成します。なお、アプリ内の手順（CloudFormation の部分を除く）は引き続き必要です。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/aws/connect-aws-organization-to-aikido.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
