Zscaler MDR requests access to all regions in your AWS account to scan for resources. We’re granted limited, primarily read-only access to a specific set of AWS services within each customer account through an assigned IAM role with restricted privileges.
Control Tower’s Region Deny Setting
When configuring an AWS Control Tower Landing Zone and selecting regions for governance, there are two options for configuring region deny at the landing zone and the Organization Unit (OU) level. The region deny setting prevents accounts from enumerating resources or fetching guard duty alerts. The OU level control allows for customization that can be used to grant Zscaler MDR access.
.png?sv=2026-02-06&spr=https&st=2026-09-12T19%3A02%3A07Z&se=2026-09-12T19%3A13%3A07Z&sr=c&sp=r&sig=SqBvcOTfJgYlSPHjSvAcY%2FUuI8Vp27UKb%2B0PJIVwm%2BQ%3D)
Grant Zscaler MDR Access and Use Region Deny
You must enable the CT.MULTISERVICE.PV.1 control in Control Tower.
Ensure that it:
Applies to all OUs and accounts in the organization
Allows access for all governed regions
Grants access to the Zscaler MDR IAM role provisioned in each account.
Example: arn:aws:iam::*:role/redcanary-partner-access
.png?sv=2026-02-06&spr=https&st=2026-09-12T19%3A02%3A07Z&se=2026-09-12T19%3A13%3A07Z&sr=c&sp=r&sig=SqBvcOTfJgYlSPHjSvAcY%2FUuI8Vp27UKb%2B0PJIVwm%2BQ%3D)
Once the CT.MULTISERVICE.PV.1 control is enabled and applies to all accounts, edit the Landing Zone settings and change the region deny setting to Not enabled.
For more information, see Configure the Region deny control.