Views:

Connect an AWS account in one of the supported China regions (cn-north-1 or cn-northwest-1) to Cloud Accounts using CloudFormation deployment.

AWS accounts in China regions require a different connection process than accounts in other AWS regions. China region accounts must use single account deployment with CloudFormation (Terraform deployment is not supported). AWS China regions (cn-north-1, cn-northwest-1) operate as a separate partition, isolated from standard AWS regions. Before you begin, review the region limitations for connecting an AWS account to Cloud Accounts.
Important
Important
  • AWS China regions only support single account deployment with CloudFormation. AWS Organizations and Terraform deployment are not available for China regions.
  • If you plan to use Private VPC with your AWS China region account, you must configure specific domains and VPC endpoints before connecting. For more information, see Private VPC requirements for AWS China regions.

Procedure

  1. Sign in to TrendAI Vision One™.
  2. Go to Cloud AccountsAWS.
  3. Click Add Account.
  4. On the Deployment Method screen, select CloudFormation.
    Note
    Note
    Terraform deployment is not supported for AWS China regions.
  5. Select Single AWS account.
    Note
    Note
    AWS Organizations deployment is not supported for AWS China regions.
  6. Click Next.
  7. On the General Information screen, specify the following:
    • Account Name: Enter a name for this connection
    • Description (optional): Enter a description
    • Region: Select one of the supported China regions:
      • cn-north-1 (Beijing)
      • cn-northwest-1 (Ningxia)
    Note
    Note
    When you select a China region for deployment, Server & Workload Protection scanning regions will be limited to cn-northwest-1.
  8. Click Next.
  9. On the Features and Permissions screen, select the features you want to enable for this account.
    The following features are supported in AWS China regions:
    • Core features
    • Cyber Risk Exposure Management - Cloud account assessment
    • Real-Time Posture Monitoring
    • Agentless Vulnerability and Threat Detection
    • Cloud Detections for VPC Flow Logs
    • Container Protection for Amazon ECS
    Note
    Note
    Features that do not support China regions will be disabled and cannot be enabled.
  10. Click Next.
  11. On the Launch screen, click Launch Stack to open the AWS CloudFormation console in a new tab.
  12. In the AWS CloudFormation console, review the stack details and click Create stack.
  13. After the stack deployment completes successfully, return to the TrendAI Vision One™ console and click Done.
    The AWS account appears in Cloud Accounts with the selected features enabled. It can take a few minutes for the AWS account to appear.