Deleted AWS Control Tower and SSO and now cannot disable the other accounts created.

0

All the accounts created in here i cannot login back into it anymore because i already deleted the SSO and Control Tower. I am trying to delete the organizations but i cant because its not empty. I want to disable the accounts but cant log back in

2개 답변
2

If you're unable to log in to the AWS Management Console because you've deleted Single Sign-On (SSO) and Control Tower, and you're trying to delete the AWS Organizations but can't because it's not empty. Kindly follow these below steps :- https://docs.aws.amazon.com/signin/latest/userguide/troubleshooting-sign-in-issues.html

Recover Access to the AWS Accounts:- If you have access to the email addresses associated with the AWS accounts, you can initiate a password reset process for each account. This will allow you to regain access to the accounts and manage them through the AWS Management Console.

Contact AWS Support :- if you're unable to recover access to the accounts through the standard password reset process. They may be able to assist you in regaining access to the accounts. Delete or Disable Unused AWS Resources:

Once you regain access to the AWS accounts, review the resources that were provisioned within those accounts. Delete or disable any resources that are no longer needed or associated with the SSO or Control Tower setup. This may include IAM roles, policies, S3 buckets, EC2 instances, VPCs, etc.

Once everything is cleaned up, review and update access controls and permissions for the AWS accounts to ensure that they are configured correctly based on your organization's requirements.

Hope it clarifies and if it does I would appreciate answer to be accepted so that community can benefit for clarity, thanks ;)

profile picture
전문가
답변함 한 달 전
profile picture
전문가
검토됨 한 달 전
1
수락된 답변

Hi There

Since you still have AWS Organizations configured, you can get the root email address for the individual accounts through the AWS Organizations service console. Navigate to AWS Organizations, select an OU, then select an account. THe root email address will be shown under Account Details.

Once you have the email addresses, you need to do a password reset as specified here: https://repost.aws/knowledge-center/control-tower-account-root-user-access

After you have root access, you can close the accounts.

Even if you cant access the member accounts, you can still close them via AWS Organizations in the management account. Follow the instructions here: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_close.html

profile pictureAWS
전문가
Matt-B
답변함 한 달 전
profile picture
전문가
검토됨 한 달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠