Account Factory - Existing Accounts

In this lab, we’ll look at bringing in existing AWS Account(s) created outside of the AWS Control Tower under the AWS Control Tower’s governance. The account(s) should already be a member of the organization under AWS Control Tower management. We’ll walk through the following two options as in this lab:

Option 1: Enroll a single account into AWS Control Tower using Account Factory.

Option 2: Register an entire organizational unit into AWS Control Tower using extend governance option.

For this lab, you choose between one of the options above and proceed with respective steps.

Terminologies

  • An Enrolled account is an AWS account that is managed by AWS Control Tower.
  • A Not enrolled account is an existing AWS account that was created outside of AWS Control Tower. It is not managed by AWS Control Tower.
  • A Registered organizational unit (OU) is an OU that was created in the AWS Control Tower or Registered with AWS Control Tower. It is managed by AWS Control Tower.
  • An Unregistered organizational unit (OU) is created through AWS Organizations. AWS Control Tower does not manage this OU.
  • When an account is enrolled in AWS Control Tower, it means that specific baselines and guardrails are applied to that account.
  • When an OU is registered with AWS Control Tower, it means that specific baselines and guardrails are applied to that OU and all of its accounts.

Create a Non-Account Factory organizations member Account or Organizational Unit.

In this section we’ll create an AWS Account and an Organizational Unit directly from AWS Organiations to simulate an existing account/ou scenerio.

Create a non-Account-factory member Account vis AWS Organizations

  • in the AWS Console go to the AWS Organizations service
  • click Add account
  • click Create account
    • AWS Account name : Lab3
    • Email : <alias>+Lab3@<realm>
    • IAM role name : <leave blank>
    • Click Create
  • on the top ribbon, click on Organize accounts
  • in the left hand panel click on Root
  • in the center panel click + New organizational unit
  • Create organizational unit

    • Name of organizational unit : Old
    • click Create organizational unit
  • at the bottom of the centre pane, select the account Lab3

  • click Move

  • Move any AWS accounts one at a time to this OU

    • click on Old
    • click Move

Review the OU and Account in AWS Control Tower

  • in the AWS Console go to the Control Tower service
  • in the left-hand panel, click on Organizational units
  • in the main panel you will see Core and Labs marked as Registered but Old as Unregistered
  • Control Tower now supports enrolling a single AWS account or up to 300 AWS accounts in a single OU.
    • Option 1 - If you wish to enroll an OU select the radio button next to the OU you want to register. At the upper right, select Register OU. More details here: Register an existing organizational unit
    • Option 2 - If you wish to enroll a single AWS Account, in the left-hand panel, click on Accounts, in the center panel you will now see the account named Lab3. More details here: Enroll the account in Control Tower

Option 1 - Enroll one existing account

If the account was not created in AWS Organizations or invited into AWS organizations follow these instructions:

Click to Expand if account is not part of AWS Organiztions