This article shows you how to connect every account in an AWS Organization, or in a specific Organizational Unit (OU), to Cye Cloud Posture Solution by deploying a CloudFormation StackSet from your organization's master account.
Overview
Cye Cloud Posture Solution, the Cloud Security Posture Management (CSPM) component of the Cye platform, scans each AWS account through a read-only IAM role created by a CloudFormation stack. A StackSet deploys that stack to all the accounts in your organization or OU in one operation, so you do not have to connect each child account by hand.
Connect the Master Account First: Connect the organization master account the same way as a single account, then use it to deploy the StackSet to the child accounts.
Deploy with Service-Managed Permissions: The integration StackSet uses the service-managed permission model so CloudFormation can create stack instances in the target organization or OUs.
Confirm in the Console: The onboarded accounts appear on the accounts page several minutes after the StackSet completes.
1. Connect the organization master account
1. Connect the organization master account
The child accounts are connected from the master account, so the master account has to be connected first.
Go to the AWS console and log in to your organization master account.
Follow Connecting Your AWS Account to connect the master account to Cye Cloud Posture Solution.
3. Create the StackSet
3. Create the StackSet
The integration StackSet uses the service-managed permission model to deploy stack instances in the target organization or OUs. When prompted, enable the use of service-managed permissions.
Click Create StackSet.
In Amazon S3 URL, enter
https://s3.us-east-1.amazonaws.com/solvo-cft-prod/onboarding-cft-rw.jsonand click Next.Enter the following values:
Stack name:
solvo-integration-stacksetExternalId: Your tenant ID, as supplied by the support team.
RoleSuffix: Any random 15-character string of letters and numbers.
SolvoAWSAccount:
844333365856SolvoSnsTopic:
prod-onboarding-cft-completed
Click Next.
Click Next again.
Select whether to deploy the stack to all accounts in the organization or to a specific OU.
Specify the US East region.
Click Next.
Select I acknowledge that AWS CloudFormation might create IAM resources with custom names and click Submit.
4. Confirm the accounts are connected
4. Confirm the accounts are connected
The connection is established a few minutes after the StackSet finishes.
Wait for the StackSet to complete.
Log in to the console at console.solvo.cloud.
Allow several minutes for the connection to be established. After a successful connection, the onboarded AWS accounts appear on the accounts page.
Wrap-up / Next Steps
Wrap-up / Next Steps
Keep the role permissions current: When new services are added to the integration, follow Updating the Cye Cloud Posture Solution CloudFormation Template to redeploy the StackSet with the latest template.
Review the access you granted: See How Cye Cloud Posture Solution Connects to Your AWS Environment for the full list of permissions in the template.
Connect an account outside the organization: Go to Cloud Accounts > Connect account and follow Connecting Your AWS Account.







