Change email address for Log Archive and Audit accounts

0

Hi, is it not safe/possible to change email address for Log Archive and Audit accounts (automatically provisioned by Control Tower) using standard procedure? See https://docs.aws.amazon.com/controltower/latest/userguide/change-account-email.html .

As stated in the NOTE: The following procedure doesn't allow you to change the email address of a management account, log archive account, or audit account. For more information about that, see How do I change the email address associated with my AWS account? or contact AWS Support.

What's the correct procedure?

Thanks.

Emanuele

eborin
已提問 1 年前檢視次數 814 次
2 個答案
0

It is technically possible, but it is not formally supported. You would need to go through the documented process that you linked to here already, but then you need to update/repair the landing zone to reflect those changed account emails. You may need to do this a couple of times. What it's doing is updating the CloudFormation stack set parameters to align. Anecdotally I've heard that some customers find that some function as they should, others need a repeated update/repair before those changes propagate. I do not have first hand knowledge of making this change myself.

AWS
Roguen
已回答 1 年前
0

Yes you can change the email addresses associated with your Control Tower accounts, and per document that is one of the type of changes that are updated automatically by Control Tower, but AWS Service Catalog handles changes differently than AWS Control Tower so you may need to update Service Catalog manually as well since the Provisioned Product for vended accounts in Service Catalog will not be automatically updated to match any changes you make to your accounts. If you want your Provisioned Product to be consistent with the actual state of your vended accounts, you'd need to perform an update in Service Catalog.

AWS
debbie
已回答 1 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南