Control tower rolls out Guard rails in these 4 regions.
You can see this e.g. when you look at the Cloudformation StackSets in the CT payer account, like AWSControlTowerBP-BASELINE-CONFIG. This StackSet contains stack instances for every managed accounts in these 4 regions.
If STS is disabled in these regions then CloudFormation cannot assume the right role to deploy the template and therefore your account deployment / baselining will fail.
AWS Control Tower failed to set up your landing zone completely: AWS Control Tower is not authorized to baseline the VPC in the enrolled account.asked 3 months ago
AWS Control Tower 3.0 creates two Config Aggregators - why?asked 4 months ago
Control Tower dependency to other regions?Accepted Answerasked 3 years ago
Control Tower Cost IncreaseAccepted Answerasked 3 years ago
AWS Control Tower in GovCloudasked 2 years ago
AWS Tower Setup failed: Subscribe To AWS EC2 Serviceasked a year ago
AWS Control Tower - Deployment Errorasked a year ago
Unable to Launch AWS Control towerasked 8 months ago
Issue building Control tower landing zone on a new account - AWS Control Tower setup failed. Be sure your account is subscribed to the AWS EC2 service, then try againAccepted Answerasked 10 months ago
Control Tower that the parent organizational unit is not enrolled in AWS Control Tower, when it isasked a year ago