AWS Control Tower failed to set up your landing zone completely: AWS Control Tower is not authorized to baseline the VPC in the enrolled account.

0

Hi all, I got this issue when setup Control Tower. "AWS Control Tower failed to set up your landing zone completely: AWS Control Tower is not authorized to baseline the VPC in the enrolled account."

Firstly, I tried to add all required permissions, tried again but still failed. Then, I removed all the relevant settings, and policies and re-try but still failed. When I click retry, it shows more errors messages below:

"AWS Control Tower could not update your landing zone at this time. Retry updating your landing zone for access to AWS Control Tower. If the problem persists, contact AWS Support."

and

"Error Failed to assume role arn:aws:iam::3084000xxxxx:role/service-role/AWSControlTowerAdmin"

For the assume role error, I've created and manually added all the required permission but still failed.

Please share your experienced on this issues. I'm stuck now.

질문됨 2년 전2146회 조회
1개 답변
0

Hello!

AWS Control Tower doesn't support the AWS default VPC. Deploying one causes the account to enter a Tainted state. When it is in that state, you cannot update the account through AWS Service Catalog. You must delete the default VPC that you added, and then you will be able to update the account.

AWS
debbie
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠