Untangle management account

0

I've inherited an AWS org that is a bit of a typical mess. The management account is also where the prod workloads are deployed.

Is there a way to enable this, perhaps creating a new account and re-casting it to be the new management account?

Moving resources is out of the question.

This seems like a common scenario I've already seen many times.

1개 답변
0
수락된 답변

Hi There

AWS best practice is to avoid running workloads in the management account. See https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html

Here's a high level overview of how to approach it:

  1. Create a new Org using AWS Control Tower, this way you get a clean Landing Zone with all of the AWS foundational best practices in place. See https://docs.aws.amazon.com/whitepapers/latest/organizing-your-aws-environment/basic-organization.html
  2. Invite the existing accounts to the new org
  3. AFter all of the child accounts have been moved, delete AWS Organizations and invite the existing Prod account to the new org as a child account.

Moving resources is out of the question.

Can you expand on this a bit?

profile pictureAWS
전문가
Matt-B
답변함 한 달 전
  • But what happens with the billing and any secured discounts on the mgtm account?

    Can you expand on this a bit?

    I do not want to move any resources from one account to another.

  • BIlling- You will continue to get 2 bills until you bring the existing org management account into the new org. As soon as you bring the child accounts into the new org, billing becomes the responsibility of that management account.

    Discounts- What discounts are you referring to? If these are discounts provided by your AWS Account team, your account manager will be able to cover this. If you are referring to savings plans/reserved instances, you can share these from any account. If you currently purchase these in the org management account, you should coordinate the movement of accounts with expiring plans, because you wont be able to move them to the new org without moving the account. The RI's and SP's stay with the account they are purchased in.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠