Appx.Add accounts via AWS Organization
You can use AWS Organizations to manage automated deployment of monitored accounts. In AWS CloudFormation, you can configure StackSet to deploy the Agent stack in the target Organizational Unit (OU). After you have configured the deployment, the Agent stack will be automatically deployed to the specified region of the account under the OU. Finally, you need to deploy the IT stack to the Organizations management account or the corresponding CloudFormation delegated account under Organizations, then, you can add member accounts via Organizations.
Steps
- Deploy Admin CloudFormation stack in the Admin account.
- Register delegated administrator in StackSets in Organization’s management account. For more information, refer to Register a delegated administrator.
- Deploy IT CloudFormation Stack.
- Create a role for the solution Admin API.
- Create StackSet for Agent CloudFormation Stack.
- Deploy to Organization/OU(s).
- Add member account via Organizations.
- Retrieve deployment stacks and member accounts.