account move in different OU, impact on TGW or Subnets
A customer has the following question:
In linked account x
I have a VPC which subnets are shared with specific OUs and TGW which also shared with specific OUs. Now account x
right now is in OU a
and I want to move it to OU b
.
My question: is there any risk of performing such move of account x
from a
to b
OU?
Reason why I am asking is because these subnets, and TGW has business critical apps running in it.
In docs I didn't find any notes that would warn about any issues, but can some please confirm if such move is a safe thing to do for the customer.
Generally low-risk, but check the below notes. I've done this in the past with 0 impact to the accounts.
The longer answer is: "it depends". Remembering the primary goal of Organizational OUs as a way to group, manage, and apply policies on that organized accounts, you'll need to make sure that you don't have any organization policies on the new OU you plan on moving the account to.
Take a look at the doc example and think about the accounts under the OU at the bottom right inheriting multiple policies that the account on the far left does not have applied. Ie: Make sure you don't have org policies that will impact the account in its new OU home.
Relevant questions
New VPC Subnets and Transit Gateway attachment
Accepted AnswerMulticast support with a VPC and Transit Gateway (TGW)
Accepted Answerasked 2 years agoTransit Gateway shared with AWS Resource Access Manager (AWS RAM) identify all accounts as external
Accepted Answerasked 3 years agowhat is shared services VPC/Account ?
Accepted Answerasked 3 years agoError “All subnets do not belong to the user’s account” when setting up MWAA environment in Control Tower config w/ VPCs shared across accounts
asked 3 months agoWhat is the maximum supported throughput of a transit gateway
asked 3 months agoaccount move in different OU, impact on TGW or Subnets
Accepted Answerasked 2 years agoTransit Gateway Peering - Cross Accounts Not Sharing Payer ID
Accepted Answerasked 2 years agoWorkspaces deployment in multi account - Control Tower
Accepted Answerasked 2 years agoTransit Gateway attachment cost to VPC and subnets
Accepted Answerasked 2 years ago