Soru

Zorluk: OrtaMulti-Account Governance and Organizational Structure

A company is implementing a multi-account governance framework using AWS Organizations and AWS Control Tower. The solutions architect needs to onboard an existing standalone AWS account that hosts a legacy production workload into the organization. The landing zone must apply the standard enterprise security baselines and detective guardrails without disrupting the legacy workload.

What is the correct sequence of steps to successfully onboard and govern this existing account using AWS Control Tower?

  1. 1Initiate and send an organization invitation to the standalone account from the Organizations management account.
  2. 2Sign in to the standalone account as the root user and accept the invitation to join the organization.
  3. 3Move the joined account from the Root organizational unit (OU) to a target OU that is registered with AWS Control Tower.
  4. 4Enroll the account in AWS Control Tower using the AWS Control Tower console or AWS Service Catalog Account Factory.

Cevap

The correct order to onboard the existing standalone account is: first, send the organization invitation from the management account; second, accept the invitation from the standalone account; third, move the joined account to a registered organizational unit (OU); and fourth, enroll the account in AWS Control Tower.
The correct sequence begins with initiating the invite from the management account, followed by accepting it in the member account. Next, the member account must be moved to an Organizational Unit that is registered with AWS Control Tower, and finally, the account is enrolled to apply the standard baselines and policies.

Adım Adım Çözüm

1
Invite the standalone account to the Organization.
The invitation is pending and visible in the standalone account.
Before managing the account, it must become a member of the AWS Organization.
2
Accept the invitation in the standalone account.
The standalone account becomes a member account under the Root OU.
The owner of the standalone account must approve the join request to delegate billing and management.
3
Move the account to an OU registered with AWS Control Tower.
The account is positioned within the governance scope of AWS Control Tower.
AWS Control Tower manages accounts that reside in registered OUs.
4
Enroll the account in AWS Control Tower.
Baseline guardrails, Service Control Policies, and StackSets are deployed to the account.
This step applies the security posture and governance baseline without recreating the account.

Anahtar Kavram

Onboarding existing accounts into AWS Control Tower requires first making them part of the AWS Organization, placing them in a registered OU, and then executing the enrollment process.
Bu soruyu puanla