Submit containment preferences
To configure containment preferences for your account or organization, create an AWS Support case
In your support case, specify the following information:
When configured, AWS Security Incident Response executes executes the authorized containment actions during active security incidents to help protect your environment.
Your AWS Organizations ID or specific account IDs where containment actions should be authorized.
Your preferred containment option.
Note
AWS Security Incident Response executes containment actions only when configured with the appropriate preferences and after the required AWS CloudFormation StackSet is deployed to grant necessary permissions.