Control Tower Enrollment Error

0

Hi,

I created some (5) new accounts via the AWS Organization (which I shouldn't have, should be using the Control Tower) and trying to enroll them into the Control Tower. It was fine for the first 2 accounts, however, things started to fail for the remaining 3.

I'm getting error as follows:

AWS Control Tower cannot enroll the account. There's an error in the provisioned product in AWS Service Catalog: ProvisionedProduct with Name: null and Id: pp-joe7ydrgkjqja doesn't exist
AWS Control Tower cannot enroll the account. There's an error in the provisioned product in AWS Service Catalog: ProvisionedProduct with Name: null and Id: pp-pqglnk2ru554w doesn't exist

I've gone through the troubleshooting guide and also have the AWSControlTowerExecution role setup. The first 2 accounts were enrolled with no problems, so not sure why subsequent ones failed. I can't find any of the Id in the Service Catelog serice as well and there isn't any errors there.

Something seems to be broken at the backend. Anyone can help?

Thanks!

asked a year ago1602 views
1 Answer
0

Please check if the user has been added to the appropriate permission group. You may need to add your IAM Identity Center user to one of these permission groups: AWSAccountFactory (for end-user access) or AWSServiceCatalogAdmins (for admin access).

profile pictureAWS
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions