Enable GuardDuty in a Primary Region (us-east-1).
GuardDuty is a regional service and must be activated separately in each required region.
Repeat for a Secondary Region (us-west-2).
Security best practices recommend enabling GuardDuty in multiple regions, even if they are not actively used. GuardDuty costs nothing in inactive regions unless activity is detected (SCP blocks resources from being deployed).
We also delegated administration to the SecurityAudit account.
Auto-Enable GuardDuty for All Future Accounts.
This ensures that any newly created AWS accounts within the organization automatically have GuardDuty enabled. Auto-enable only applies to new accounts, not existing ones.