Submit containment preferences
To configure containment preferences for your account or organization, create an AWS Support case
In your support case, specify the following information:
Your AWS Organizations ID or specific account IDs where containment actions should be authorized.
Your preferred containment option.
When configured, AWS Security Incident Response executes the authorized containment actions during active security incidents to help protect your environment.
Note
AWS Security Incident Response executes containment actions only when configured with the appropriate preferences and after the required AWS CloudFormation StackSet is deployed to grant necessary permissions.