New account creation gives error via Control Tower Account factory console but works from Service Catalog console.

0

Got an issue where Control Tower Account Factory could not create new account and error received was "AWS Control Tower cannot enrol the account. There's an error in the provisioned product in AWS Service Catalog: Specified ProvisioningArtifactId does not exist: pa-kckebjcahx3gi".

I checked in Service Catalog and can see that sso user is already added under "Access" starting as "aws-reserved/sso.amazonaws.com/AWSReservedSSO_AWSAdministratorAccessxxxxxxxxx" (this was used to login into the account)

Account gets vended via Service Calatog console successfully. The above error comes only via account factory console. Any idea what is missing and why account creation does not work via Account Factory Console?

I read other repost similar articles but was not much helpful.

1개 답변
0

one of the reason is if you login as root, it will not allow you to create accounts. If you login as IAM/ Identity center user, you should be able to create accounts using account factory.

AWS
답변함 3달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠