- GuardDuty now supports AWS Organizations declarative policies for centralized enablement across all accounts and Regions
- Admins can define policies at the organization root, OUs, or individual accounts with default and per‑Region overrides, automatically applying to existing and new accounts
- Policy‑driven enablement cannot be overridden via the GuardDuty console or API, ensuring consistent threat detection