Example SQL Queries
aws . securityhub .get_master_account;
Description
This method is deprecated. Instead, use GetAdministratorAccount .
The Security Hub console continues to use GetMasterAccount . It will eventually change to use GetAdministratorAccount . Any IAM policies that specifically control access to this function must continue to use GetMasterAccount . You should also add GetAdministratorAccount to your policies to ensure that the correct permissions are in place after the console begins to use GetAdministratorAccount .
Provides the details for the Security Hub administrator account for the current member account.
Can be used by both member accounts that are managed using Organizations and accounts that were invited manually.
Table Definition
Column Name Column Data Type
_aws_profile Input Column The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.
STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) )
Show child fields _aws_profile.account_id The AWS account id
_aws_profile.assumed_role_arn The ARN of the assumed role
_aws_profile.name The unique name of the profile.
_aws_profile.organization Information about this profile's membership in the AWS organization.
Show child fields _aws_profile.organization.account_name The name of account speciifed by the organization
_aws_profile.organization.id The organization id
_aws_profile.organization.master_account Show child fields _aws_profile.organization.master_account.email The organization master account email address
_aws_profile.organization.master_account.id The organization master account id
_aws_profile.organization.parents[] Show child fields _aws_profile.organization.parents[].id The id of the parent
_aws_profile.organization.parents[].name The name of the parent
_aws_profile.organization.parents[].tags[] Show child fields _aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type The type of parent can be an organization unit or a root
_aws_profile.organization.tags[] Show child fields _aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type The type of profile, either 'credentials' or 'assumed_role'
_aws_profile.via_profile_name This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
_aws_region Input Column The AWS region to use.
VARCHAR
master A list of details about the Security Hub administrator account for the current member account.
STRUCT( "account_id" VARCHAR, "invitation_id" VARCHAR, "invited_at" TIMESTAMP_S, "member_status" VARCHAR )
Show child fields master.account_id The account ID of the Security Hub administrator account that the invitation was sent from.
master.invitation_id The ID of the invitation sent to the member account.
master.invited_at The timestamp of when the invitation was sent.
master.member_status The current status of the association between the member and administrator accounts.