AWS SSO with Control Tower Accounts

0

Hello team! Do I need to configure SSO separately for the additional accounts I added using AFT or it will provide SSO automatically?

1 Answer
0
Accepted Answer

Hi as Manny_A mentioned, an AFT account request will create an Administrator user in Identity Centre(SSO) for the new account (This is actually a built in feature of Control Tower). However that's the only thing it will do.

To configure other users, groups, or permission sets for Accounts in your Organization, you will have to create separate code to achieve this. You will execute the code against the Org Management account (where Identity Centre is). Or if you have delegated that to another account, it will be there.

profile pictureAWS
answered 6 months ago
profile picture
EXPERT
reviewed a month ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions