3 Answers
- Newest
- Most votes
- Most comments
4
I resolved this issue by changing the KMS key policy, review this https://docs.aws.amazon.com/en_us/controltower/latest/userguide//configure-kms-keys.html#kms-key-policy-update
answered 3 years ago
1
Hi There
I recommend performing the steps in Decommission Control Tower and manually removing resources. Specifically, check this section that outlines the resources that need to be manually removed before setting up CT again: https://docs.aws.amazon.com/controltower/latest/userguide/known-issues-decommissioning.html

This worked after I deleted AWSControlTowerBP-BASELINE-CLOUDTRAIL-MASTER stack.
This was the reason in my case since I have opted in for KMS for encryption