Hi guys my production environment is in the management account.Now I want to set up Control Tower for my existing organization and both the production environment and the Control Tower landing zone will be in the same region. I know that during the setup process, Control Tower sets up guardrails. Can that affect my production environment? I plan to move the production environment to another account later.

Enabling Control Tower does not affect your organization's existing AWS accounts.
If you move under the Control Tower OU, guardrails will be applied and there may be an impact.

If it is a management account, I think it is managed in the root OU, so I don't think it will be restricted by SCP etc.

