Control Tower - Unable to add new account to the Security OU?

2

Hello,

I'm setting up a new Control Tower managed organization using https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/ as a reference. This suggests creating a Security Tooling account under the Security OU for services such as GuardDuty, Security Hub, etc.

When I try to create this account in the Service Catalogue, the Security OU isn't available to select for the ManagedOrganiszationalUnit preference (all other OU are though). How can I add a CT managed account to the Security OU?

Thanks!

  • The Audit account that is in the Security OU corresponds to the Security Tooling account so you can use that one for services such as Security Hub, Guard Duty, etc etc..

질문됨 2년 전1614회 조회
2개 답변
3
수락된 답변

Hi, unfortunately there seems to be a disparity in the documentation. While the Security Reference Architecture describes the Security Tooling account under the Security OU. Control Towers functionality does not allow the provisioning of an Account into it's default created OU, which happens to be called Security, as this is the location for core accounts that Control Tower creates. The field advice I give customers on this currently, and often help them deploy, is to create a new OU for the Security Tooling account. There are also mandatory guardrails applied to that default OU, that may limit your usage, and it's best to keep accounts that you create in their own OU's to allow full flexibility in deployment and configuration.

profile pictureAWS
답변함 2년 전
profile picture
전문가
검토됨 한 달 전
0

Thanks for the explanation, Jimmy. I've passed on this feedback via the SRA page so hopefully this will be picked up.

답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠