Control Tower - Account Factory - No launch paths found for resource: prod-2dlxxxx

1

Hi,

I'm currently suing an AWS Organization deployed with ControlTower.

I've creates a new PermissionSet with AdministratorAccess AWS managed polocies that I applied to the management account .

When I go to the controlTower Account Factory I got the following message "No launch paths found for resource: prod-2dlxxxx"

Can You please help me with that issue ?

Regards

FabienG
asked a year ago1162 views
1 Answer
1
Accepted Answer

Hi, That is likely due to the Permission Set/Role you are using not being allowed to use the Account Factory Product/Portfolio in Service Catalog. https://docs.aws.amazon.com/controltower/latest/userguide/troubleshooting.html#no-launch-paths-found

Alongside the notes above, to fix the permissions you can: Go to the Service Catalog service in the AWS Console. Under Administration in the left menu, select Portfolios. You should see a "AWS Control Tower Account Factory Portfolio". Click on that name. There will be a tab "Access", select that and you will see a list of identities that have permissions to use this portfolio and products. Use the Grant Access button to add your Role to that list. Due to being logged in via SSO and Permission Sets, your role will match something like aws-reserved/sso.amazonaws.com/<region>/AWSReservedSSO_<Permission Set name>_<unique identifier>

profile pictureAWS
answered a year ago
  • Thanks for your help and quick answer. This is working fine.

  • I followed the advice, logged in as administrator, and I still get the error message. Any other suggestions?

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions