- Newest
- Most votes
- Most comments
I have replicated your scenario of setting up centralized backups following the same AWS guidance (https://aws.amazon.com/blogs/storage/build-centralized-cross-region-backup-architecture-with-aws-control-tower/) in my environment where LZA was already deployed.
My Implementation Steps:
Created backup administrator account through AWS Organizations (not Control Tower) Created central backup account through AWS Organizations (not Control Tower) Created multi-region KMS key as documented Updated Landing Zone Accelerator with enable backup option Enabled AWS Backup without any issues.
However, I notice you mentioned creating accounts via Control Tower. It's not recommended to create backup administrator and central backup accounts through Control Tower - they should be created through AWS Organizations directly.
For Your SCP Limit Issue:
From your error I can see that you have hit the maximum number of SCPs that has been attached to OU.
I would recommend you to check number of SCP's attached to your OU's .
Moreover, I don't have access to resources that is attached to you OU. I would recommend you to open a case with AWS Support to assist you better.
Sources
Build centralized cross-Region backup architecture with AWS Control Tower | AWS Storage Blog
Enable backups - AWS Control Tower
Enable backup on moved accounts - AWS Control Tower
answered 10 months ago
Relevant content
asked 2 years ago
asked 3 years ago
asked 3 years ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 3 years ago
- AWS OFFICIALUpdated 3 years ago
