How do I add a member account to the AWS Control tower managed Organization?

0

Hey everyone,

I know the process of inviting a standalone account to Organization but I thought would like to double check if there are additional steps to keep in mind, because this standalone account has all Prod workloads. This account does not have to be under the control tower. We will be migrating the workloads to respective newly created accounts/environments in the new Organization.

I wanted to confirm if the automatically created cross account roles will be sufficient? I dont have any major SCPs or control tower policies yet, just want to make sure that the Prod workloads dont go down when I enroll the new member account.

Thanks in advance. Have a great day.

Qasim
질문됨 4달 전560회 조회
2개 답변
2
수락된 답변

Hello - there are a few things to consider that are highlighted in the doc below but for the most part you should be fine enrolling the account especially if you are only applying the default mandatory controls to that OU. Read through the article below as it covers this topic in detail.

https://docs.aws.amazon.com/controltower/latest/userguide/enroll-account.html

AWS
전문가
답변함 4달 전
profile picture
전문가
검토됨 2달 전
0

Greetings,

There are some considerations to inviting an already existing account to your AWS Control Tower managed Organization. The account will need to leave the previous AWS Organization and any pre-existing Config Recorder and Channels need to be deleted prior to enrollment. There is a known 4-step script process you can run that will search for any pre-existing configs and channels to delete theme. You can run your own script as well and it should find and delete it.

I have included the documentation below [1] that describes some of the requirements prior to enrolling the account. The next page in the link "Single Account" and "Resolving Failures" should help to assist. What may occur after disenrolling the account from the previous AWS Organization and AWS Control Tower OU is that the account may not have the OrganizationAccountAccessRole and you will need to manually add this role to successfully enroll the account. The AWSControlTowerExecution role will need to be manually added as well [2]. I have included the steps to fulfill the remaining prerequisites below [3].

OrganizationAccountAccessRole - Allows access to member accounts in your organization to manage services and assign roles. AWSControlTowerExecution - Baselines member account with Control Tower and allows you to manage the account.

I hope this information helps! Please let me know if you have any questions and I will be happy to assist!

---References---

[1] - Enrolling Existing AWS Accounts https://catalog.workshops.aws/control-tower/en-US/enrolling-existing

[2] - Creating the OrganizationAccountAccessRole in an invited member account https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html

[3] - Steps to fulfill the remaining prerequisites: https://docs.aws.amazon.com/controltower/latest/userguide/enroll-account.html

profile pictureAWS
답변함 2달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠