AWSControlTowerExecution recreation catch22

0

Long story short I was tidying up an account I have deleted AWSControlTowerExecution role and I'm unable to re-enrol the account nor am I able to create the AWSControlTowerExecution role as it is blocked by a SCP. I only see two options as I need the exact name the account currently has. I still have cli/console admin access to the account. The reason I need the name is for aft as the account in question is called AFT-Management. I only see three ways out

  1. Delete the account although I can't afford to wait 90 days
  2. Bypass SCP somehow
  3. The name AFT-Management isn't a requirement of AFT

Any Ideas?

Kyle R
已提問 7 個月前檢視次數 180 次
2 個答案
1

Have you tried temporarily removing the SCP from the account (this is done in the Org Management account), re-creating the role and then re-applying the SCP back to the account? There's no way to bypass the SCP other than removing it temporarily.

AWS
LondonX
已回答 7 個月前
1

Hello,

With console and CLI access to the account, you can try running the below command if the account is under an organization [1].

aws organizations list-accounts

The command will list all the accounts in an organization and their names under the 'Name' property.

Another way to get the full name of the account, click to the account profile on the top right corner of the console > under the drop down menu, click on the 'Account' option > then look for 'Full name' under Contact Information.

[1] https://docs.aws.amazon.com/cli/latest/reference/organizations/list-accounts.html

AWS
支援工程師
已回答 7 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南