AWS Control Tower failed to set up your landing zone completely: AWS Control Tower is not authorized to baseline the VPC in the enrolled account.

0

Hi all, I got this issue when setup Control Tower. "AWS Control Tower failed to set up your landing zone completely: AWS Control Tower is not authorized to baseline the VPC in the enrolled account."

Firstly, I tried to add all required permissions, tried again but still failed. Then, I removed all the relevant settings, and policies and re-try but still failed. When I click retry, it shows more errors messages below:

"AWS Control Tower could not update your landing zone at this time. Retry updating your landing zone for access to AWS Control Tower. If the problem persists, contact AWS Support."

and

"Error Failed to assume role arn:aws:iam::3084000xxxxx:role/service-role/AWSControlTowerAdmin"

For the assume role error, I've created and manually added all the required permission but still failed.

Please share your experienced on this issues. I'm stuck now.

已提问 2 年前2146 查看次数
1 回答
0

Hello!

AWS Control Tower doesn't support the AWS default VPC. Deploying one causes the account to enter a Tainted state. When it is in that state, you cannot update the account through AWS Service Catalog. You must delete the default VPC that you added, and then you will be able to update the account.

AWS
debbie
已回答 2 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则