Account Factory - Existing Accounts

In this lab, we’ll look at bringing in existing AWS Account(s) created outside of the AWS Control Tower under the AWS Control Tower’s governance. The account(s) should already be a member of the organization under AWS Control Tower management. We’ll walk through the following two options as in this lab:

Option 1: Enroll a single account into AWS Control Tower using Account Factory.

Option 2: Register an entire organizational unit into AWS Control Tower using extend governance option.

For this lab, you choose between one of the options above and proceed with respective steps.

Terminologies

  • An Enrolled account is an AWS account that is managed by AWS Control Tower.
  • A Not enrolled account is an existing AWS account that was created outside of AWS Control Tower. It is not managed by AWS Control Tower.
  • A Registered organizational unit (OU) is an OU that was created in the AWS Control Tower or Registered with AWS Control Tower. It is managed by AWS Control Tower.
  • An Unregistered organizational unit (OU) is created through AWS Organizations. AWS Control Tower does not manage this OU.
  • When an account is enrolled in AWS Control Tower, it means that specific baselines and guardrails are applied to that account.
  • When an OU is registered with AWS Control Tower, it means that specific baselines and guardrails are applied to that OU and all of its accounts.

Create a Non-Account Factory organizations member Account and Organizational Unit.

In this section we’ll create an AWS Account and an Organizational Unit directly from AWS Organiations to simulate an existing account/ou scenerio.

Create a non-Account-factory member Account via AWS Organizations

  • In the AWS Console go to the AWS Organizations service
  • Choose Add an AWS account
  • Choose Create an AWS account and type-in below values:
    • AWS Account name : Lab3
    • Email : <alias>+Lab3@<realm>
    • IAM role name : <leave default value>
    • Choose Create AWS Account

Create an Organizational Unit in AWS Organizations

  • Under AWS Organizations, AWS accounts, Select checkbox for Root
  • On the right side, expand Actions
  • Under Organizational unit, choose Create new Create OU

  • Create organizational unit

    • Name of organizational unit : Old
    • click Create organizational unit Create Old OU

Move the account in to AWS Organization

  • Under AWS Organizations, AWS accounts, Select checkbox for Lab3
  • On the right side, expand Actions
  • Under AWS account, choose Move
  • Select Old under Destination
  • Choose Move AWS account

Review the OU and Account in AWS Control Tower

Review OU list

  • In the AWS Console go to the Control Tower service
  • Choose Organizational units in the left side panel
  • You will see Security, Sandbox, and Labs marked as Registered but Old as Unregistered
  • AWS Control Tower now supports enrolling a single AWS account or up to 300 AWS accounts in a single OU.
    • Option 1 - If you wish to enroll an OU select the radio button next to the OU you want to register. At the upper right, select Register OU. More details here: Register an existing organizational unit
    • Option 2 - If you wish to enroll a single AWS Account, in the left-hand panel, click on Accounts, in the center panel you will now see the account named Lab3. More details here: Enroll the account in Control Tower

Option 1 - Enroll one existing account

If the account was not created in AWS Organizations or invited into AWS organizations follow these instructions:

Click to Expand if account is not part of AWS Organiztions

Option 2 - Register an existing organizational unit

Click to Expand to register an existing organizational unit

Review the OU and Accounts in AWS Control Tower

  • In the AWS Console go to the Control Tower service
  • In the lefthand panel, click on Organizational units
  • Option 1 - in the main panel you will see the OU Labs listed as Registered
    • Click on Labs
    • In the Details pane, you will Labs is listed as Compliant
    • In the Accounts pane, you will see the account named Lab3 listed as enrolled
  • Option 2 - in the main panel you will see the newly registerd OU as Registered
    • Click on newly registerd OU
    • In the Details pane, you will newly registerd OU is listed as Compliant
    • In the Accounts pane, you will see all your AWS accounts listed as Enrolled

References

Enable AWS Control Tower on existing organizations and accounts

Failure Error that Mentions AWS Config

Copyright 2021, Amazon Web Services, All Rights Reserved.