Configuration
The Configuration page is the permanent home for enabling additional Security Hub engines and reviewing the home region of each enabled engine. It is always available from the Security Hub sidebar, regardless of how many engines are currently enabled.
Accessing Configuration
Click Configuration in the Security Hub sidebar. The page is available at /securityhub/configuration.
Why This Page Exists
When you first open the Security Hub and no engines are enabled, the Overview page shows the Enable Security Hub panel directly. Once your first engine is enabled and you navigate back to Overview, the stat cards appear instead; the selector is no longer shown there.
The Configuration page hosts the same capability panel permanently, headed Security capabilities when embedded there, so you always have a place to enable additional engines after your first one is live. The Enable {Engine} call-to-action that appears in the sidebar for an engine that has not been set up also links here.
Capabilities Tab
The first tab on the Configuration page is labeled Capabilities. It displays one card per available Security Hub engine:
- Security Hub CSPM: Standards-based cloud security posture management
- Amazon GuardDuty: Threat detection across accounts and regions
- Amazon Macie: S3 data-security posture and sensitive-data findings
- Amazon Inspector: Vulnerability management across EC2 instances, container images, Lambda functions, and code repositories
- Amazon Detective: Behavior-graph investigation of the IAM users and roles involved in a security event
Each card shows the engine name, a brief description, and a list of key capabilities. The card's button changes depending on the engine's state:
| Engine state | Button label | Action |
|---|---|---|
| Not enabled | Enable | Starts the engine's setup wizard |
| Already enabled | Configure | Opens the engine's settings |
An engine that is already enabled shows a green Enabled indicator in the card alongside the Configure button.
A capability that this deployment cannot offer keeps its card, with its description and capability list intact, but shows the reason in place of the Enable button. Today this applies only to Amazon Detective, on a self-hosted deployment that is not paired with CloudKeeper SaaS; such a deployment also has no Detective entry in the sidebar. See Availability on self-hosted deployments.
A Foundational section below the engine cards shows the AWS Config (recording) status (the number of account × region cells currently recording) with a Manage button that links to AWS Config.
Enabling a Second Engine After CSPM
If CSPM is already enabled and you want to add GuardDuty:
- Click Configuration in the Security Hub sidebar.
- Select the Capabilities tab (it is selected by default).
- Locate the Amazon GuardDuty card.
- Click Enable.
- Complete the GuardDuty setup wizard.
- After submission, you are taken to a progress screen while GuardDuty is being enabled.
The same procedure applies in the reverse order (enabling CSPM after GuardDuty).
Each engine is independent. Enabling a second engine does not affect the first engine's configuration, data, or enrollment state.
Regions Tab
The second tab on the Configuration page is labeled Regions. It lists the home region of each currently enabled engine. For engines that use a delegated administrator, that is the region where the administrator and finding aggregator are configured. For Amazon Inspector, which has no delegated administrator, the home region is simply the default region Prism uses and the one it falls back to, it aggregates nothing. For Amazon Detective, which builds one behavior graph per region rather than aggregating into one, the home region is likewise just the default region and aggregates nothing.
Regions shown here are read-only. To change an engine's home region or manage linking regions, use that engine's own Settings page:
If no engines are enabled, the Regions tab shows an empty state with the message "No enabled engines to show regions for."
The Capabilities tab loads engine data from a capabilities API and shows loading skeletons while it resolves. If the cards do not finish loading after a few seconds, reload the page. See Security Hub Issues if the problem persists.
Related Pages
- Security Hub CSPM: Enabling, CSPM setup wizard
- GuardDuty: Enabling, GuardDuty setup wizard
- Macie: Enabling, Macie setup wizard
- Inspector: Enabling, Inspector setup wizard
- Detective: Enabling, Detective setup wizard
- Security Hub, Security Hub overview